{"components":{"securitySchemes":{"bearerAuth":{"scheme":"bearer","type":"http"}}},"info":{"title":"Treliso customer API","version":"0.1.0"},"openapi":"3.1.0","paths":{"/api/accounts":{"get":{"description":"List accounts the customer belongs to, including their role.","operationId":"list_accounts","parameters":[],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"items":{"items":{"properties":{"id":{"format":"uuid","type":"string"},"name":{"type":"string"},"role":{"type":"string"}},"required":["id","name","role"],"type":"object"},"type":"array"}},"required":["items"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"read"},"post":{"description":"Create an account owned by the authenticated customer.","operationId":"create_account","parameters":[],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"name":{"type":"string"}},"required":["name"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"account_id":{"format":"uuid","type":"string"}},"required":["account_id"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/accounts/{id}/members":{"post":{"description":"Add or update an account member; owners and administrators only.","operationId":"add_member","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"role":{"enum":["admin","member"],"type":"string"},"user_id":{"format":"uuid","type":"string"}},"required":["role","user_id"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"ok":{"type":"boolean"}},"required":["ok"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/accounts/{id}/members/{user}":{"delete":{"description":"Remove an account member and their VM grants; account owners cannot be removed.","operationId":"remove_member","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"path","name":"user","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"ok":{"type":"boolean"}},"required":["ok"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/operations/{id}":{"get":{"description":"Inspect an asynchronous VM lifecycle operation.","operationId":"get_operation","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"attempts":{"format":"int32","type":"integer"},"id":{"format":"uuid","type":"string"},"kind":{"type":"string"},"state":{"type":"string"},"vm_id":{"format":"uuid","type":"string"}},"required":["id","vm_id","kind","state","attempts"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"read"}},"/api/ssh-keys/challenges":{"post":{"description":"Request a short-lived challenge to prove ownership of an SSH public key.","operationId":"key_challenge","parameters":[],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"public_key":{"type":"string"}},"required":["public_key"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"challenge":{"type":"string"},"challenge_id":{"format":"uuid","type":"string"},"namespace":{"type":"string"}},"required":["challenge_id","challenge","namespace"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/ssh-keys/challenges/{id}":{"post":{"description":"Enroll an SSH key using its signed challenge; each challenge may be used once.","operationId":"enroll_key","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"signature":{"type":"string"}},"required":["signature"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"fingerprint":{"type":"string"},"key_id":{"format":"uuid","type":"string"}},"required":["key_id","fingerprint"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/ssh-keys/{id}":{"delete":{"description":"Revoke one of the customer's SSH keys.","operationId":"revoke_key","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"ok":{"type":"boolean"}},"required":["ok"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/vms":{"get":{"description":"List the VMs accessible through account roles or explicit VM grants.","operationId":"list_vms","parameters":[],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"items":{"items":{"properties":{"account_id":{"format":"uuid","type":"string"},"desired":{"type":"boolean"},"host_id":{"format":"uuid","type":"string"},"id":{"format":"uuid","type":"string"},"name":{"type":"string"},"slot_id":{"format":"uuid","type":"string"},"state":{"type":"string"}},"required":["id","account_id","name","slot_id","host_id","desired","state"],"type":"object"},"type":"array"}},"required":["items"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"read"},"post":{"description":"Provision a VM with a generated two-word name and return its asynchronous operation ID; poll get_operation for readiness.","operationId":"create_vm","parameters":[{"in":"header","name":"Idempotency-Key","required":false,"schema":{"maxLength":128,"minLength":1,"type":["string","null"]}}],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"account_id":{"format":"uuid","type":"string"}},"required":["account_id"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"operation_id":{"format":"uuid","type":"string"},"vm":{"properties":{"account_id":{"format":"uuid","type":"string"},"desired":{"type":"boolean"},"host_id":{"format":"uuid","type":"string"},"id":{"format":"uuid","type":"string"},"name":{"type":"string"},"slot_id":{"format":"uuid","type":"string"},"state":{"type":"string"}},"required":["id","account_id","name","slot_id","host_id","desired","state"],"type":"object"}},"required":["vm","operation_id"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/vms/{id}":{"delete":{"description":"Delete a VM and retire its public domains and TCP routes.","operationId":"delete_vm","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"operation_id":{"format":"uuid","type":"string"}},"required":["operation_id"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"},"get":{"description":"Inspect an accessible VM and its lifecycle state.","operationId":"get_vm","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"account_id":{"format":"uuid","type":"string"},"desired":{"type":"boolean"},"host_id":{"format":"uuid","type":"string"},"id":{"format":"uuid","type":"string"},"name":{"type":"string"},"slot_id":{"format":"uuid","type":"string"},"state":{"type":"string"}},"required":["id","account_id","name","slot_id","host_id","desired","state"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"read"}},"/api/vms/{id}/deployments":{"get":{"description":"List managed applications inside a VM.","operationId":"list_deployments","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"items":{"items":{"properties":{"command":{"type":"string"},"directory":{"type":"string"},"id":{"format":"uuid","type":"string"},"last_exit_code":{"format":"int32","type":["integer","null"]},"name":{"type":"string"},"pid":{"format":"int32","minimum":0,"type":["integer","null"]},"restarts":{"format":"int32","minimum":0,"type":"integer"},"status":{"type":"string"}},"required":["id","name","directory","command","status","restarts"],"type":"object"},"type":"array"}},"required":["items"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}},"/api/vms/{id}/deployments/{deployment}":{"get":{"description":"Inspect a managed application's command, supervisor state and restart count.","operationId":"get_deployment","parameters":[{"in":"path","name":"deployment","required":false,"schema":{"default":"app","pattern":"^[a-zA-Z0-9_-]{1,64}$","type":"string"}},{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"command":{"type":"string"},"directory":{"type":"string"},"id":{"format":"uuid","type":"string"},"last_exit_code":{"format":"int32","type":["integer","null"]},"name":{"type":"string"},"pid":{"format":"int32","minimum":0,"type":["integer","null"]},"restarts":{"format":"int32","minimum":0,"type":"integer"},"status":{"type":"string"}},"required":["id","name","directory","command","status","restarts"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"},"put":{"description":"Replace a named managed application with uploaded files and a start command; it persists across reconnects and guest boots.","operationId":"deploy_app","parameters":[{"in":"path","name":"deployment","required":false,"schema":{"default":"app","pattern":"^[a-zA-Z0-9_-]{1,64}$","type":"string"}},{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"header","name":"Idempotency-Key","required":false,"schema":{"maxLength":128,"minLength":1,"type":["string","null"]}}],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"command":{"maxLength":4096,"minLength":1,"type":"string"},"cwd":{"maxLength":4096,"minLength":1,"type":["string","null"]},"env":{"additionalProperties":{"maxLength":4096,"type":"string"},"maxProperties":64,"propertyNames":{"maxLength":128,"minLength":1},"type":["object","null"]}},"required":["command"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"command":{"type":"string"},"directory":{"type":"string"},"id":{"format":"uuid","type":"string"},"last_exit_code":{"format":"int32","type":["integer","null"]},"name":{"type":"string"},"pid":{"format":"int32","minimum":0,"type":["integer","null"]},"restarts":{"format":"int32","minimum":0,"type":"integer"},"status":{"type":"string"}},"required":["id","name","directory","command","status","restarts"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}},"/api/vms/{id}/deployments/{deployment}/logs":{"get":{"description":"Read a bounded range of a managed application's stdout or stderr log; data is base64.","operationId":"deployment_logs","parameters":[{"in":"path","name":"deployment","required":false,"schema":{"default":"app","pattern":"^[a-zA-Z0-9_-]{1,64}$","type":"string"}},{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"query","name":"length","required":false,"schema":{"default":65536,"format":"int32","maximum":262144,"minimum":1,"type":["integer","null"]}},{"in":"query","name":"offset","required":false,"schema":{"format":"int64","minimum":0,"type":["integer","null"]}},{"in":"query","name":"stream","required":false,"schema":{"enum":["stdout","stderr",null],"type":["string","null"]}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"data":{"type":"string"},"eof":{"type":"boolean"},"offset":{"format":"int64","minimum":0,"type":"integer"}},"required":["offset","data","eof"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}},"/api/vms/{id}/deployments/{deployment}/stop":{"post":{"description":"Stop a managed application and disable automatic restarts, including after a guest reboot.","operationId":"stop_deployment","parameters":[{"in":"path","name":"deployment","required":false,"schema":{"default":"app","pattern":"^[a-zA-Z0-9_-]{1,64}$","type":"string"}},{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"ok":{"type":"boolean"}},"required":["ok"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}},"/api/vms/{id}/domains":{"get":{"description":"List a VM's domains and DNS verification requirements.","operationId":"list_domains","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"items":{"items":{"properties":{"cname_target":{"type":"string"},"domain_id":{"format":"uuid","type":"string"},"fly_dns_requirements":{},"hostname":{"type":["string","null"]},"state":{"type":"string"},"txt_name":{"type":"string"},"txt_value":{"type":"string"}},"required":["domain_id","state","txt_name","txt_value","cname_target"],"type":"object"},"type":"array"}},"required":["items"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"read"},"post":{"description":"Register a customer hostname and return its DNS verification requirements.","operationId":"add_domain","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"hostname":{"type":"string"}},"required":["hostname"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"cname_target":{"type":"string"},"domain_id":{"format":"uuid","type":"string"},"fly_dns_requirements":{},"hostname":{"type":["string","null"]},"state":{"type":"string"},"txt_name":{"type":"string"},"txt_value":{"type":"string"}},"required":["domain_id","state","txt_name","txt_value","cname_target"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/vms/{id}/domains/{domain}":{"delete":{"description":"Retire a VM's customer domain.","operationId":"remove_domain","parameters":[{"in":"path","name":"domain","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"ok":{"type":"boolean"}},"required":["ok"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/vms/{id}/exec":{"post":{"description":"Run a command inside a VM, returning an execution ID to poll. Timeout defaults to 60 seconds, maximum 900.","operationId":"exec_vm","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"header","name":"Idempotency-Key","required":false,"schema":{"maxLength":128,"minLength":1,"type":["string","null"]}}],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"command":{"maxLength":4096,"minLength":1,"type":"string"},"cwd":{"maxLength":4096,"minLength":1,"type":["string","null"]},"env":{"additionalProperties":{"maxLength":4096,"type":"string"},"maxProperties":64,"propertyNames":{"maxLength":128,"minLength":1},"type":["object","null"]},"timeout_seconds":{"default":60,"format":"int32","maximum":900,"minimum":1,"type":["integer","null"]}},"required":["command"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"execution_id":{"format":"uuid","type":"string"},"state":{"type":"string"}},"required":["execution_id","state"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}},"/api/vms/{id}/exec/{execution}":{"delete":{"description":"Cancel a guest command and terminate its process group.","operationId":"cancel_execution","parameters":[{"in":"path","name":"execution","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"ok":{"type":"boolean"}},"required":["ok"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"},"get":{"description":"Poll a guest command's status, separate stdout/stderr, exit code and output truncation flags.","operationId":"get_execution","parameters":[{"in":"path","name":"execution","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"error":{"type":["string","null"]},"execution_id":{"format":"uuid","type":"string"},"exit_code":{"format":"int32","type":["integer","null"]},"signal":{"format":"int32","type":["integer","null"]},"state":{"type":"string"},"stderr":{"type":"string"},"stderr_truncated":{"type":"boolean"},"stdout":{"type":"string"},"stdout_truncated":{"type":"boolean"}},"required":["execution_id","state","stdout","stderr","stdout_truncated","stderr_truncated"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}},"/api/vms/{id}/files":{"get":{"description":"Read a bounded range from a guest file; data is base64 unless encoding is utf8.","operationId":"read_file","parameters":[{"in":"query","name":"encoding","required":false,"schema":{"enum":["base64","utf8",null],"type":["string","null"]}},{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"query","name":"length","required":false,"schema":{"default":65536,"format":"int32","maximum":262144,"minimum":1,"type":["integer","null"]}},{"in":"query","name":"offset","required":false,"schema":{"format":"int64","minimum":0,"type":["integer","null"]}},{"in":"query","name":"path","required":true,"schema":{"maxLength":4096,"minLength":1,"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"data":{"type":"string"},"eof":{"type":"boolean"},"offset":{"format":"int64","minimum":0,"type":"integer"}},"required":["offset","data","eof"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}},"/api/vms/{id}/grants/{user}":{"delete":{"description":"Revoke a member's explicit access to a VM.","operationId":"remove_grant","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"path","name":"user","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"ok":{"type":"boolean"}},"required":["ok"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"},"post":{"description":"Grant VM access to an existing account member.","operationId":"add_grant","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"path","name":"user","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"ok":{"type":"boolean"}},"required":["ok"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/vms/{id}/start":{"post":{"description":"Start a VM; poll the returned operation ID.","operationId":"start_vm","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"operation_id":{"format":"uuid","type":"string"}},"required":["operation_id"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/vms/{id}/stop":{"post":{"description":"Stop a VM and immediately revoke its active allocations.","operationId":"stop_vm","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"operation_id":{"format":"uuid","type":"string"}},"required":["operation_id"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/vms/{id}/tcp":{"post":{"description":"Reserve an available public TCP port mapped to a guest port.","operationId":"add_tcp","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"guest_port":{"format":"int32","maximum":65535,"minimum":1,"type":"integer"}},"required":["guest_port"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"guest_port":{"format":"int32","minimum":0,"type":"integer"},"public_port":{"format":"int32","minimum":0,"type":"integer"}},"required":["public_port","guest_port"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/vms/{id}/tcp/{port}":{"delete":{"description":"Retire a VM's public TCP reservation.","operationId":"remove_tcp","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"path","name":"port","required":true,"schema":{"format":"int32","maximum":65535,"minimum":1,"type":"integer"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"ok":{"type":"boolean"}},"required":["ok"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"manage"}},"/api/vms/{id}/uploads":{"post":{"description":"Begin a verified upload to a guest path; default maximum file size is 64 MiB.","operationId":"begin_upload","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"header","name":"Idempotency-Key","required":false,"schema":{"maxLength":128,"minLength":1,"type":["string","null"]}}],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"length":{"description":"Expected decoded file bytes. Server policy defaults to 64 MiB; hard limit 1 GiB.","format":"int64","maximum":1073741824,"minimum":0,"type":"integer"},"path":{"maxLength":4096,"minLength":1,"type":"string"},"sha256":{"pattern":"^[0-9a-fA-F]{64}$","type":"string"}},"required":["length","path","sha256"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"complete":{"type":"boolean"},"received":{"format":"int64","minimum":0,"type":"integer"},"upload_id":{"format":"uuid","type":"string"}},"required":["upload_id","received","complete"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}},"/api/vms/{id}/uploads/{upload}":{"delete":{"description":"Abort an incomplete upload and remove its temporary guest file.","operationId":"abort_upload","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"path","name":"upload","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"ok":{"type":"boolean"}},"required":["ok"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}},"/api/vms/{id}/uploads/{upload}/chunks":{"put":{"description":"Write a base64 upload chunk of at most 256 KiB decoded; identical retries are safe.","operationId":"write_upload_chunk","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"path","name":"upload","required":true,"schema":{"format":"uuid","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"contentEncoding":"base64","maxLength":349528,"minLength":1,"type":"string"},"offset":{"format":"int64","minimum":0,"type":"integer"}},"required":["data","offset"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"complete":{"type":"boolean"},"received":{"format":"int64","minimum":0,"type":"integer"},"upload_id":{"format":"uuid","type":"string"}},"required":["upload_id","received","complete"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}},"/api/vms/{id}/uploads/{upload}/complete":{"post":{"description":"Verify the upload's length and SHA-256, then atomically replace its guest destination.","operationId":"complete_upload","parameters":[{"in":"path","name":"id","required":true,"schema":{"format":"uuid","type":"string"}},{"in":"path","name":"upload","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"complete":{"type":"boolean"},"received":{"format":"int64","minimum":0,"type":"integer"},"upload_id":{"format":"uuid","type":"string"}},"required":["upload_id","received","complete"],"type":"object"}}},"description":"Success"},"400":{"description":"Invalid arguments"},"401":{"description":"Authentication required"},"403":{"description":"Insufficient scope or resource permission"},"404":{"description":"Resource not found"}},"security":[{"bearerAuth":[]}],"x-required-scope":"vm_access"}}}}