Skip to main content

Zyvor Fabric REST API Documentation

Base URL​

http://localhost:9095/api

Authentication​

Most endpoints require a valid JWT token passed via the Authorization header:

Authorization: Bearer <token>

Obtain a token:

# Read the auto-generated admin password (first startup)
PASSWORD=$(sudo cat /var/lib/zyvor-fabricd/.admin_password)

# Login
curl -X POST http://localhost:9095/api/auth/login \
-H "Content-Type: application/json" \
-d "{\"username\": \"admin\", \"password\": \"$PASSWORD\"}"

Unauthenticated requests receive a 401 Unauthorized response. The /api/auth/login, /health, and /readyz endpoints are accessible without authentication. When auth is disabled in config, all endpoints are accessible without a token.

GET /readyz returns JSON {"ok", "store", "fluxvm"} (HTTP 503 when not ready). Use it for load-balancer / Kubernetes readiness; keep /health for liveness.

Overview​

The API exposes 780+ REST endpoints and 3 WebSocket endpoints organized into the categories below. This document lists the key endpoints in each category. All request and response bodies use JSON.


Auth​

User authentication and session management.

MethodEndpointDescription
POST/auth/sign-inAuthenticate and obtain a token
POST/auth/logoutInvalidate the current token
POST/auth/refreshRefresh an expiring token
GET/auth/meGet the current authenticated user
POST/auth/usersCreate a new user
GET/auth/usersList users
PUT/auth/users/:idUpdate a user
DELETE/auth/users/:idDelete a user
POST/auth/rolesCreate a role
GET/auth/rolesList roles

Enterprise Identity (SCIM)​

SCIM 2.0 lifecycle provisioning and group-to-role sync for Entra ID / Okta, layered on top of an existing OIDC/SAML/LDAP auth provider. Admin routes use a normal Fabric JWT; the /scim/v2/* data-plane routes use a dedicated, profile-scoped bearer token instead (minted below), not a Fabric JWT. See docs/scim-identity.md for the full walkthrough and security properties.

MethodEndpointDescription
GET/identity/scim/profilesList provisioning profiles
POST/identity/scim/profilesCreate a provisioning profile
PUT/identity/scim/profiles/:idUpdate a profile
DELETE/identity/scim/profiles/:idDelete a profile (must have no active SCIM resources)
GET/identity/scim/tokensList SCIM bearer tokens
POST/identity/scim/tokensMint a SCIM bearer token for a profile (plaintext shown once)
DELETE/identity/scim/tokens/:idRevoke a SCIM bearer token

SCIM data-plane routes (outside /api, under /scim/v2, bearer-token auth):

MethodEndpointDescription
GET/scim/v2/ServiceProviderConfigSCIM discovery: supported features
GET/scim/v2/ResourceTypesSCIM discovery: resource types
GET/scim/v2/SchemasSCIM discovery: schemas
GET/scim/v2/UsersList/filter users
POST/scim/v2/UsersCreate a user
GET/scim/v2/Users/:idGet a user
PUT/scim/v2/Users/:idReplace a user
PATCH/scim/v2/Users/:idPatch a user (activate/deactivate, etc.)
DELETE/scim/v2/Users/:idDeprovision a user
GET/scim/v2/GroupsList/filter groups
POST/scim/v2/GroupsCreate a group
GET/scim/v2/Groups/:idGet a group
PUT/scim/v2/Groups/:idReplace a group
PATCH/scim/v2/Groups/:idPatch a group (membership changes)
DELETE/scim/v2/Groups/:idDelete a group

OpenStack Compatibility​

Experimental OpenStack wire-protocol façade (Keystone v3, Nova v2.1, Glance v2, Neutron v2.0, Cinder v3) mounted on the same listen port as Fabric, outside /api. Not the same as SCIM (/scim/v2). Catalog endpoint URLs come from daemon.public_url / ZYVOR_FABRICD_PUBLIC_URL (else listen + TLS). See docs/openstack-compat.md and the hands-on Tutorial 08.

MethodEndpointDescription
POST/identity/v3/auth/tokensIssue Keystone-style token (X-Subject-Token)
GET/identity/v3/auth/tokensValidate token
GET/identity/v3/auth/catalogService catalog (requires token)
GET/compute/v2.1/flavorsList Nova flavors (m1.tiny … m1.xlarge)
GET/POST/compute/v2.1/serversList / create servers
POST/compute/v2.1/servers/:id/actionstart / stop / reboot
GET/image/v2/imagesList Glance images
GET/network/v2.0/networksList Neutron networks
GET/POST/volume/v3/:project_id/volumesList / create Cinder volumes

VM Management​

Core virtual machine lifecycle operations.

MethodEndpointDescription
GET/app/vmsList all VMs
POST/app/vmsCreate a new VM
GET/app/vms/:nameGet VM details
DELETE/app/vms/:nameDelete a VM
POST/app/vms/:name/startStart a VM
POST/app/vms/:name/stopStop a VM
POST/app/vms/:name/restartRestart a VM
POST/app/vms/:name/pausePause a VM
POST/app/vms/:name/resumeResume a paused VM
GET/app/vms/:name/metricsGet VM resource metrics
GET/app/vms/:name/statusGet detailed VM status

Example: Create a VM​

POST /api/vms
Content-Type: application/json

{
"name": "myvm",
"image": "/path/to/image.qcow2",
"cpus": 4,
"memory": 4096
}

Response (201 Created):

{
"name": "myvm",
"state": "stopped",
"cpus": 4,
"memory": 4096,
"image": "/path/to/image.qcow2"
}

Start a VM with Options​

The POST /vms/:name/start endpoint accepts an optional JSON body with VMStartOptions to control how the active VM driver launches the VM. All fields are optional and default sensibly when omitted.

VMStartOptions only applies to a VM's first launch (translated into an FluxVM CreateVmRequest). Most fields are honored: cpus/memory (from the VM record), network_tap/network_user_mode, linux/initrd/firmware, extra_args, and bind_mounts (each entry becomes a launch-time virtiofs share, auto-mounted in the guest via cloud-init — no live bind-mount equivalent exists for a real hardware VM). The rest have no FluxVM equivalent and fail with a clear error rather than silently being ignored: tpm, secure_boot, vsock, extra_drives, bind_users, credentials/load_credentials, smbios11, directory.

POST /api/vms/myvm/start
Content-Type: application/json

{
"scope": "system",
"directory": "/path/to/rootfs",
"kvm": true,
"secure_boot": false,
"vsock": true,
"vsock_cid": 42,
"tpm": true,
"tpm_state": "auto",
"linux": "/boot/vmlinuz",
"initrd": ["/boot/initrd.img"],
"network_tap": true,
"network_user_mode": false,
"firmware": "/usr/share/ovmf/OVMF.fd",
"discard_disk": true,
"grow_image": "50G",
"smbios11": ["custom.vendor-string=hello"],
"notify_ready": true,
"uuid": "550e8400-e29b-41d4-a716-446655440000",
"slice": "vm.slice",
"properties": ["MemoryMax=4G", "CPUQuota=200%"],
"register": true,
"private_users": "1000:65536",
"bind_mounts": [
{ "source": "/host/data", "destination": "/vm/data", "read_only": false }
],
"extra_drives": ["/extra/disk.raw"],
"bind_users": ["myuser"],
"bind_user_shell": "/bin/bash",
"bind_user_groups": ["wheel"],
"forward_journal": "/var/log/vm.journal",
"pass_ssh_key": true,
"ssh_key_type": "ed25519",
"console": "interactive",
"background": "44",
"quiet": false,
"credentials": [
{ "id": "passwd.hashed-password.root", "value": "$y$..." }
],
"load_credentials": [
{ "id": "ssh.authorized_keys.root", "path": "/root/.ssh/authorized_keys" }
],
"extra_args": ["enforcing=0"]
}

VMStartOptions Field Reference​

FieldTypeDescription
scope"system" | "user"Manager scope (omitted = auto: system when root, user otherwise)
directorystringRoot filesystem directory (alternative to image)
kvmbool?KVM acceleration (null = omitted, uses Zyvor Fabric default)
secure_bootbool?Secure Boot firmware (null = omitted, uses Zyvor Fabric default)
vsockbool?VSock networking (null = omitted, uses Zyvor Fabric default)
vsock_cidu32?VSock CID (null = omitted, uses Zyvor Fabric default)
tpmbool?TPM support (null = omitted, uses Zyvor Fabric default)
tpm_statestringTPM state path, "auto", or "off"
linuxstringKernel image path for direct kernel boot
initrdstring[]Initrd paths (multiple are merged)
network_tapboolCreate a TAP device, requires root (default: false)
network_user_modeboolUse user mode networking (default: false)
firmwarestringFirmware definition file path
discard_diskbool?Process discard/trim requests (null = omitted, Zyvor Fabric default: yes)
grow_imagestringGrow image to size, e.g. "50G". Validated format: digits + optional size suffix
smbios11string[]SMBIOS Type #11 vendor strings (must not start with io.systemd.credential)
notify_readybool?Wait for READY=1 from VM init (null = omitted, Zyvor Fabric default: yes)
uuidstringMachine UUID (must be valid UUID format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx)
slicestringSystemd slice for scope unit (must end with .slice)
propertiesstring[]Resource-control properties only (e.g. "MemoryMax=4G", "CPUQuota=200%")
registerbool?Unused — no equivalent on the current (FluxVM) driver
private_usersstringUser namespace mapping (e.g. "1000:65536")
bind_mountsBindMount[]Host-to-VM bind mounts (paths must not contain ..)
extra_drivesstring[]Additional disk images or block devices
bind_usersstring[]Host users to bind into the VM (system users and UIDs < 1000 are blocked)
bind_user_shellstringShell for bound users: "yes", "no", or an absolute path
bind_user_groupsstring[]Auxiliary groups for bound users
forward_journalstringForward VM journal to host (file or dir)
pass_ssh_keybool?Generate and pass SSH key (null = omitted, Zyvor Fabric default: yes)
ssh_key_typeenumSSH key type: "ed25519", "ecdsa", "rsa"
consoleenumConsole mode: "interactive", "read-only", "native", "gui"
backgroundstringTerminal background color (ANSI SGR)
quietboolSuppress Zyvor Fabric status output (default: false)
credentialsCredential[]Credentials via --set-credential
load_credentialsLoadCredential[]Credentials loaded from file via --load-credential
extra_argsstring[]Extra kernel command line arguments (must not start with -)

BindMount object: { "source": string, "destination": string?, "read_only": bool }

Credential object: { "id": string, "value": string } — id must be alphanumeric/dot/hyphen/underscore (no colons)

LoadCredential object: { "id": string, "path": string } — path is the file to load the credential from ("value" is accepted as an alias for backward compatibility)

See the note above for which fields FluxVM actually honors versus rejects with an error.

Snapshots​

Point-in-time VM state capture and restoration.

MethodEndpointDescription
GET/app/vms/:name/snapshotsList snapshots for a VM
POST/app/vms/:name/snapshotsCreate a snapshot
GET/app/vms/:name/snapshots/:idGet snapshot details
DELETE/app/vms/:name/snapshots/:idDelete a snapshot
POST/app/vms/:name/snapshots/:id/revertRevert VM to snapshot

Storage​

Disk and volume management.

MethodEndpointDescription
GET/app/storage/poolsList storage pools
POST/app/storage/poolsCreate a storage pool
GET/app/storage/pools/:idGet pool details
DELETE/app/storage/pools/:idDelete a storage pool
GET/app/storage/volumesList volumes
POST/app/storage/volumesCreate a volume
DELETE/app/storage/volumes/:idDelete a volume
POST/app/storage/volumes/:id/resizeResize a volume
POST/app/storage/volumes/:id/attachAttach volume to a VM
POST/app/storage/volumes/:id/detachDetach volume from a VM

Distributed Storage​

Cluster-wide storage management.

MethodEndpointDescription
GET/distributed-storage/clustersList storage clusters
POST/distributed-storage/clustersCreate a storage cluster
GET/distributed-storage/clusters/:idGet cluster details
DELETE/distributed-storage/clusters/:idDelete a storage cluster

Networking​

Virtual network and interface management.

MethodEndpointDescription
GET/networksList virtual networks
POST/networksCreate a virtual network
GET/networks/:idGet network details
PUT/networks/:idUpdate a network
DELETE/networks/:idDelete a network
GET/app/vms/:name/interfacesList VM network interfaces
POST/app/vms/:name/interfacesAttach a network interface
DELETE/app/vms/:name/interfaces/:idDetach a network interface

System​

Daemon health, configuration, and system information.

MethodEndpointDescription
GET/healthLiveness check (plain OK)
GET/readyzReadiness (store + FluxVM /readyz; 503 if not ready)
GET/app/system/infoSystem information
GET/app/system/configGet daemon configuration
PUT/app/system/configUpdate daemon configuration
GET/metricsPrometheus-format metrics

Quotas​

Resource usage limits per user or project.

MethodEndpointDescription
GET/app/quotasList all quotas
POST/app/quotasCreate a quota
GET/app/quotas/:idGet quota details
PUT/app/quotas/:idUpdate a quota
DELETE/app/quotas/:idDelete a quota
GET/app/quotas/:id/usageGet current usage against quota

Schedules​

Scheduled VM operations (start, stop, snapshot, backup).

MethodEndpointDescription
GET/app/schedulesList schedules
POST/app/schedulesCreate a schedule
GET/app/schedules/:idGet schedule details
PUT/app/schedules/:idUpdate a schedule
DELETE/app/schedules/:idDelete a schedule
POST/app/schedules/:id/triggerManually trigger a schedule

Audit​

Administrative action audit trail.

MethodEndpointDescription
GET/app/audit/logsQuery audit log entries
GET/app/audit/logs/:idGet a specific audit entry
GET/app/audit/summaryGet audit summary statistics

Analytics​

Usage and performance analytics.

MethodEndpointDescription
GET/app/analytics/overviewPlatform-wide analytics summary
GET/app/analytics/vmsPer-VM analytics
GET/app/analytics/resourcesResource utilization trends
GET/app/analytics/reportsGenerate or list reports

Backups​

VM backup and restore operations.

MethodEndpointDescription
GET/app/backupsList backups
POST/app/backupsCreate a backup
GET/app/backups/:idGet backup details
DELETE/app/backups/:idDelete a backup
POST/app/backups/:id/restoreRestore a VM from backup
GET/app/backups/policiesList backup policies
POST/app/backups/policiesCreate a backup policy

Notifications​

Alert and notification management.

MethodEndpointDescription
GET/notificationsList notifications
POST/notificationsCreate a notification rule
PUT/notifications/:idUpdate a notification rule
DELETE/notifications/:idDelete a notification rule
POST/notifications/:id/acknowledgeAcknowledge a notification
GET/notifications/channelsList notification channels
POST/notifications/channelsCreate a notification channel

Templates​

VM templates for standardized provisioning.

MethodEndpointDescription
GET/app/templatesList templates
POST/app/templatesCreate a template
GET/app/templates/:idGet template details
PUT/app/templates/:idUpdate a template
DELETE/app/templates/:idDelete a template
POST/app/templates/:id/deployDeploy a VM from template

Tags​

Resource tagging and categorization.

MethodEndpointDescription
GET/tagsList all tags
POST/tagsCreate a tag
DELETE/tags/:idDelete a tag
POST/app/vms/:name/tagsTag a VM
DELETE/app/vms/:name/tags/:tagRemove a tag from a VM

Cloning​

VM cloning (full and linked).

MethodEndpointDescription
POST/app/vms/:name/cloneClone a VM
GET/app/vms/:name/clonesList clones of a VM

DRS (Distributed Resource Scheduler)​

Automatic VM placement and load balancing.

MethodEndpointDescription
GET/app/drs/configGet DRS configuration
PUT/app/drs/configUpdate DRS configuration
GET/app/drs/recommendationsGet placement recommendations
POST/app/drs/recommendations/:id/applyApply a recommendation

Fault Tolerance​

VM fault tolerance configuration.

MethodEndpointDescription
GET/app/vms/:name/ftGet fault tolerance status
POST/app/vms/:name/ft/enableEnable fault tolerance
POST/app/vms/:name/ft/disableDisable fault tolerance

Replication​

VM replication to secondary hosts.

MethodEndpointDescription
GET/app/replication/configsList replication configurations
POST/app/replication/configsCreate a replication config
GET/app/replication/configs/:idGet replication config details
DELETE/app/replication/configs/:idDelete a replication config
POST/app/replication/configs/:id/syncTrigger manual sync

Site Recovery​

Disaster recovery and failover.

MethodEndpointDescription
GET/app/site-recovery/plansList recovery plans
POST/app/site-recovery/plansCreate a recovery plan
POST/app/site-recovery/plans/:id/testTest a recovery plan
POST/app/site-recovery/plans/:id/executeExecute failover
POST/app/site-recovery/plans/:id/reprotectReprotect after failover

Content Library​

Shared image and template repository.

MethodEndpointDescription
GET/app/content-library/itemsList library items
POST/app/content-library/itemsUpload an item
GET/app/content-library/items/:idGet item details
DELETE/app/content-library/items/:idDelete an item
POST/app/content-library/items/:id/deployDeploy from library item

Lifecycle​

VM lifecycle policies and operations.

MethodEndpointDescription
GET/app/lifecycle/policiesList lifecycle policies
POST/app/lifecycle/policiesCreate a lifecycle policy
PUT/app/lifecycle/policies/:idUpdate a lifecycle policy
DELETE/app/lifecycle/policies/:idDelete a lifecycle policy

Certificates​

TLS certificate management.

MethodEndpointDescription
GET/app/certificatesList certificates
POST/app/certificatesUpload a certificate
DELETE/app/certificates/:idDelete a certificate
POST/app/certificates/:id/renewRenew a certificate

VPN Mesh​

WireGuard-based VPN tunnels between VMs.

MethodEndpointDescription
POST/vpn-tunnelsCreate a VPN tunnel
GET/vpn-tunnelsList VPN tunnels
GET/vpn-tunnels/:idGet tunnel details
PUT/vpn-tunnels/:idUpdate a tunnel
DELETE/vpn-tunnels/:idDelete a tunnel
POST/vpn-tunnels/syncForce tunnel reconciliation
GET/vpn-tunnels/statusGet tunnel status
POST/vpn-networksCreate a VPN network
GET/vpn-networksList VPN networks
GET/vpn-networks/:idGet network details
PUT/vpn-networks/:idUpdate a network
DELETE/vpn-networks/:idDelete a network
GET/vpn-networks/statusGet network status

Example: Create a VPN Network​

POST /api/vpn-networks
Content-Type: application/json

{
"name": "dev-mesh",
"selector": { "match_labels": { "env": "dev" } },
"subnet": "10.10.0.0/24",
"topology": "full_mesh"
}

Response (201 Created):

{
"id": "...",
"name": "dev-mesh",
"topology": "full_mesh",
"subnet": "10.10.0.0/24",
"enabled": true
}

Packet Mirror​

Traffic mirroring for VM debugging.

MethodEndpointDescription
POST/mirror-sessionsCreate a mirror session
GET/mirror-sessionsList mirror sessions
GET/mirror-sessions/:idGet session details
PUT/mirror-sessions/:idUpdate a session
DELETE/mirror-sessions/:idDelete a session
POST/mirror-sessions/syncForce mirror reconciliation
GET/mirror-sessions/statusGet session status

NAT Gateway​

Advanced NAT: masquerade, SNAT, DNAT, hairpin.

MethodEndpointDescription
POST/nat-rulesCreate a NAT rule
GET/nat-rulesList NAT rules
GET/nat-rules/:idGet rule details
PUT/nat-rules/:idUpdate a rule
DELETE/nat-rules/:idDelete a rule
POST/nat-rules/syncForce NAT reconciliation
GET/nat-rules/statusGet rule status
POST/nat-poolsCreate a SNAT pool
GET/nat-poolsList SNAT pools
GET/nat-pools/:idGet pool details
DELETE/nat-pools/:idDelete a pool
POST/nat-gatewaysCreate a NAT gateway
GET/nat-gatewaysList NAT gateways
GET/nat-gateways/:idGet gateway details
DELETE/nat-gateways/:idDelete a gateway

Network Monitor​

Per-VM bandwidth monitoring and alerting.

MethodEndpointDescription
POST/monitor-policiesCreate a monitor policy
GET/monitor-policiesList monitor policies
GET/monitor-policies/:idGet policy details
PUT/monitor-policies/:idUpdate a policy
DELETE/monitor-policies/:idDelete a policy
POST/monitor-policies/syncForce monitor reconciliation
GET/monitor-policies/statusGet policy status
GET/network-metricsGet all VM network metrics
GET/network-metrics/:nameGet per-VM network metrics
GET/bandwidth-alertsGet active bandwidth alerts

Encryption​

Data-at-rest and key management.

MethodEndpointDescription
GET/app/encryption/keysList encryption keys
POST/app/encryption/keysCreate an encryption key
DELETE/app/encryption/keys/:idDelete an encryption key
POST/app/encryption/keys/:id/rotateRotate an encryption key
POST/app/vms/:name/encryptEncrypt a VM's disks

Resource Pools​

Resource grouping and allocation.

MethodEndpointDescription
GET/resource-poolsList resource pools
POST/resource-poolsCreate a resource pool
GET/resource-pools/:idGet pool details
PUT/resource-pools/:idUpdate a resource pool
DELETE/resource-pools/:idDelete a resource pool
POST/resource-pools/:id/assignAssign a VM to a pool

Datacenters​

Logical datacenter management.

MethodEndpointDescription
GET/app/datacentersList datacenters
POST/app/datacentersCreate a datacenter
GET/app/datacenters/:idGet datacenter details
PUT/app/datacenters/:idUpdate a datacenter
DELETE/app/datacenters/:idDelete a datacenter

Machines (removed)​

The /app/machines machinectl / systemd-machined UI was removed. Use Virtual Machines (/app/vms) and /api/vms (FluxVM).

Events​

System and VM event stream.

MethodEndpointDescription
GET/eventsQuery events
GET/events/:idGet event details
GET/events/streamSSE event stream

Autoscale​

Automatic VM scaling policies.

MethodEndpointDescription
GET/autoscale/policiesList autoscale policies
POST/autoscale/policiesCreate an autoscale policy
GET/autoscale/policies/:idGet policy details
PUT/autoscale/policies/:idUpdate a policy
DELETE/autoscale/policies/:idDelete a policy

Hotplug​

Live add/remove of devices to running VMs.

MethodEndpointDescription
POST/app/vms/:name/hotplug/cpuAdd/remove CPUs
POST/app/vms/:name/hotplug/memoryAdd/remove memory
POST/app/vms/:name/hotplug/diskAttach/detach disk
POST/app/vms/:name/hotplug/nicAttach/detach network interface

Image Builder​

Custom VM image creation.

MethodEndpointDescription
GET/image-builder/buildsList builds
POST/image-builder/buildsStart a new image build
GET/image-builder/builds/:idGet build status
DELETE/image-builder/builds/:idCancel/delete a build
GET/image-builder/recipesList build recipes
POST/image-builder/recipesCreate a build recipe

Migrations​

Disk-copy path (rsync over SSH) and native FluxVM transport (preview). See migration.md and FLUXVM-FABRIC-BOUNDARY.md.

MethodEndpointDescription
POST/migrationsStart disk-copy migration (live / offline / storage)
GET/migrationsList migrations
GET/migrations/{id}Migration status
POST/migrations/{id}/cancelCancel a migration
GET/migrations/historyCompleted / failed history
GET/migrations/readinessSSH + rsync preflight
POST/vms/{name}/migration/native/prepare-receiverArm target receiver (preview)
POST/vms/{name}/migration/native/startStart native transport (preview)
GET/vms/{name}/migration/native/statusNative status (preview)
POST/vms/{name}/migration/native/cancelCancel native (preview)
GET/vms/{name}/migration/native/network-stateDataplane migration phase
POST/migration/receivers/{id}/activateActivate receiver
DELETE/migration/receivers/{id}Abort receiver

VM Dataplane & QGA​

Proxied FluxVM Network Fabric schema v4 and guest QGA. Operator detail: fluxvm-dataplane.md.

MethodEndpointDescription
GET/vms/{name}/dataplane/statusAttach/schema; may include pod_ingress_*
GET/POST/vms/{name}/dataplane/policyGet / replace policy
GET/vms/{name}/dataplane/statsCounters; may include pod_policy
GET/vms/{name}/dataplane/flowsLRU flows
GET/vms/{name}/dataplane/effectiveMerged effective policy
GET/vms/{name}/dataplane/drop-reasonsDrop-reason histogram
GET/POST/DELETE/vms/{name}/dataplane/pod-policyPod-ingress policy
GET/POST/DELETE/dataplane/groups[/{name}]Security groups
GET/POST/DELETE/dataplane/cnp[/{name}]CNP
GET/dataplane/{health,observe,identities,ipcache}Cluster dataplane
POST/dataplane/refresh-dnsRe-resolve FQDN allowlists
POST/vms/{name}/qga/pingQGA ping
POST/vms/{name}/qga/execQGA exec
*/vms/{name}/qga/firewall/*QGA firewall helpers

Container Groups​

Secure Containers placement (Kubernetes Pod + RuntimeClass fluxvm). See container-groups.md.

MethodEndpointDescription
GET/container-groupsList groups
POST/container-groups/applyApply a ContainerGroup
GET/container-groups/{name}/statusLive status
DELETE/container-groups/{name}Delete

Agents & Sessions​

Proxied to agent-runtime when [agent_runtime] is set; otherwise 503. See tutorials/11-agent-runtime-quickstart.md. Harness runs, MCP, agent cron, signed webhooks, loops, approvals, and delegation are served by the agent-runtime process itself (:9096), not by these proxy routes. VM backup schedules under /schedules are unrelated.

MethodEndpointDescription
GET/agentsList agents
GET/sessionsList sessions
POST/sessionsCreate session
GET/sessions/{id}Session detail
POST/sessions/{id}/{hibernate|resume|cancel}Session actions
DELETE/sessions/{id}Delete session

WebSocket Endpoints​

WebSocket connections require the same authentication token, passed as a query parameter or via the initial HTTP upgrade headers.

EndpointDescription
ws://host:8080/ws/console/:vmnameInteractive terminal console (xterm.js)
ws://host:8080/ws/vnc/:vmnameVNC graphical console proxy (noVNC)
ws://host:8080/ws/eventsReal-time event stream for live UI updates

Console Example​

const ws = new WebSocket("ws://localhost:9095/ws/console/myvm?token=<token>");
ws.onmessage = (event) => term.write(event.data);
term.onData((data) => ws.send(data));

VM States​

StateDescription
runningVM is running
stoppedVM is stopped
pausedVM is paused
startingVM is being started (async, returns 202 Accepted)
stoppingVM is being stopped
failedVM encountered an error
unknownVM state cannot be determined

Error Responses​

All errors return a JSON body:

{
"error": "Error message here",
"code": "ERROR_CODE"
}

Common Status Codes:

CodeMeaning
200OK
201Created
204No Content
400Bad Request
401Unauthorized
403Forbidden
404Not Found
409Conflict
422Unprocessable Entity
429Too Many Requests
500Internal Server Error