Access-decision events for an application (gateway-security C5 / GS-7): gateway-side denials (IP allow/deny, abuse rate trips, unknown-host, suspension) aggregated per 60s window, newest-first. Org-scoped by the backend against the application's OWNER org — the caller must belong to it.
Paginated: pass limit (default 100, max 500) and an opaque cursor from
a prior page's nextCursor.
Optionalopts: RequestOptionsProbe the application's public URL and report reachability.
Optionalopts: RequestOptionsCreate an application record.
The backend accepts ONLY canonical apiVersion: v3 Application
documents (declarative-config phase 2a). Canonical documents are sent
unchanged; the legacy flat CreateApplicationRequest shape is
translated to a canonical document first (see legacyCreateTranslator.ts)
and throws ValidationError (LEGACY_CREATE_UNSUPPORTED_FIELD) for flat
fields with no canonical equivalent — nothing is silently dropped.
Optionalopts: RequestOptionsDelete an application.
Optionalopts: RequestOptionsApply a canonical declaration (the kick-off — Operation.resource is
the new version stamp) and return an Operation whose waiter polls the
deployment status to 'ready'.
Optionalopts: RequestOptionsFetch an application by id.
Optionalopts: RequestOptionsCurrent deployment FSM state plus recent history (the deploy waiter's poll target).
Optionalopts: RequestOptionsThe gateway(s) an application routes through, as a customer-facing
projection (webapp gateway panel). Per gateway: display name, kind
(managed | customer), hostname, region, real WS-heartbeat health,
last-seen, and this app's HAProxy backend server states. Managed gateways
live under the platform org and are never browsable devices — this is the
only customer read of them. Excludes SSH / capacity / other orgs' apps.
App-ownership scoped (org owns the app ⇒ may read its gateway projection).
Optionalopts: RequestOptionsthe gateway projections; an unpublished app returns [].
Lifecycle event history (newest-first, backend default limit 100).
Optionalopts: RequestOptionsLogs over a unix-ms window, optionally filtered by level/eventType.
Optionalopts: RequestOptionsAggregated metrics over a unix-ms window.
Optionalopts: RequestOptionsPre-signed metric-file URLs over a unix-ms window. Route is the
backend's /metrics-files (the legacy client's /metrics/files path
does not exist in routeDefinitions).
Optionalopts: RequestOptionsResolve the secret keys the application's current declaration references, flattened to environment variables (design/secrets-management §7). This is the DEVICE-authenticated, deploy-time path used by the agent — the only secrets endpoint that returns values, scoped to the assigned app's keys.
Optionalopts: RequestOptionsEdge request telemetry summary (ADR-0026): per-minute or hourly request
counts, status classes, bytes, derived latency percentiles, top paths /
clients / user agents, and forward-auth outcomes, as observed by Caddy on
the application's serving devices. start/end are epoch ms or ISO
instants (default: the last 24 h); granularity defaults to minute for
ranges up to 6 h and hour beyond. Every count is a sum over the range;
asOf names the newest delivered minute — Firehose buffering makes the
view near-real-time, never live.
Optionalopts: RequestOptionsPEM private key for a VM application (used by application ssh).
Optionalopts: RequestOptionsP3-1 — live workload logs collected on demand from the app's serving
device(s) over the diagnostics jobs channel (GET /applications/{id}/logs).
This is the LIVE path (works before anything reaches S3 and when an app is
wedged); getLogs is the separate historical S3 lifecycle/metrics
stream. An offline device yields a block with offline: true (not an error).
Optionalopts: RequestOptionsRaw request records (ADR-0026): every 4xx/5xx and upstream error plus a
sample of the rest, newest first, over a window of at most 6 h (default:
the last 6 h). Filter by status (5xx, 404, 400-499), a path
prefix, an exact clientIp or an access name; page with cursor.
Optionalopts: RequestOptionsForce re-realization of the CURRENT release without cutting a new version.
Bumps the app-level redeployToken so serving agents force-recreate the
workload; ref-neutral (currentReleaseVersion is untouched).
Optionalopts: RequestOptionsPer-device convergence toward the current release (a pure read). Each
device is converged iff its observedReleaseVersion strictly equals the
app's currentReleaseVersion.
Optionalopts: RequestOptionsCorrelated hop-by-hop data-path trace for an application (CP-3.1). The
backend fans collect_diagnostics to the app's gateway + serving devices
and joins the hops — gateway HAProxy backend state → WireGuard handshake
age → serving Caddy route/cert → workload health — into one
AppTraceResponse carrying a verdict (ok | fail | unknown) per hop.
timeoutMs is an optional client budget; the handler caps it under the
API Gateway 29s ceiling regardless. An offline device yields unknown
hops (with a reason) rather than an error.
Optionalopts: RequestOptionsUpdate an application record; returns the updated row.
Optionalopts: RequestOptionsSet the application's runtime status (reported per serving device).
Optionalopts: RequestOptionsWatch an ALREADY-applied deployment to a terminal state WITHOUT re-applying
(unlike deploy, which cuts a new version). This is the deploy waiter
for a stack whose versions were already cut via stacks.deploy — it polls
the same deployment-status FSM to 'ready'/'degraded' (or throws WaiterError
on error/timeout — degraded is converged-with-warning, not failure).
resource echoes the app id being watched.
Pass targetReleaseVersion — the version this deploy cut — whenever it is
known. It scopes failures to the release being waited on, so an error
reported for an EARLIER release is not mistaken for this deploy's outcome
(the create window; see deploymentPollResult).
Optionalopts: { targetReleaseVersion?: number }
sdk.applications — root namespace: application record CRUD, the deploy LRO, status/reachability, logs/metrics, plus the sub-namespace clients above (see the module doc for surface and conventions).