Skip to content
NebulaCtrldocs
HTTP APIEndpoints

Mesh

The WireGuard mesh between machines, and the access grants between environments. Each operation lists its method and path, parameters, request body, responses and an example call.

GET/agent/v1/mesh/config

Header Parameters

Authorization?string

Bearer per-node mesh credential from registration.

Response Body

application/json

application/problem+json

curl -X GET "https://example.com/agent/v1/mesh/config"
{  "$schema": "https://example.com/MeshConfigOutputBody.json",  "address": "string",  "clusterPeers": [    "string"  ],  "edgeIngressIps": [    "string"  ],  "edgeSources": [    "string"  ],  "edgeUpstreams": [    "string"  ],  "expiresAt": "2019-08-24T14:15:22Z",  "inboundTargets": [    "string"  ],  "listenPort": 0,  "mtu": 0,  "peers": [    {      "allowedIPs": [        "string"      ],      "endpoint": "string",      "persistentKeepalive": 0,      "publicKey": "string"    }  ],  "podCidr": "string",  "prefixLength": 0,  "public": true,  "serviceCidr": "string"}
POST/agent/v1/mesh/handshakes

Header Parameters

Authorization?string

Bearer per-node mesh credential from registration.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/problem+json

curl -X POST "https://example.com/agent/v1/mesh/handshakes" \  -H "Content-Type: application/json" \  -d '{    "handshakes": {      "property1": 0,      "property2": 0    }  }'
Empty
POST/agent/v1/mesh/register

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/problem+json

curl -X POST "https://example.com/agent/v1/mesh/register" \  -H "Content-Type: application/json" \  -d '{    "nodeName": "string",    "publicKey": "string",    "token": "string",    "underlayAddress": "string"  }'
{  "$schema": "https://example.com/RegisterMeshPeerOutputBody.json",  "address": "string",  "credential": "string",  "listenPort": 0,  "mtu": 0,  "podCidr": "string",  "prefixLength": 0,  "public": true,  "serviceCidr": "string"}
GET/api/v1/clusters/{id}/mesh-peers

Authorization

AuthorizationBearer <token>

An API token, sent as Authorization: Bearer <token>. A token belongs to one organization and has the role it was created with, so it needs no X-Nebula-Organization header; if you send one, it must name the token's organization.

In: header

Path Parameters

id*string

Query Parameters

includeRevoked?boolean

Also list peers removed from the mesh, with revokedAt set. Their keys are retired for good.

Response Body

application/json

application/problem+json

curl -X GET "https://example.com/api/v1/clusters/string/mesh-peers"
{  "$schema": "https://example.com/MeshPeersOutputBody.json",  "hub": {    "clusterId": "string",    "clusterName": "string",    "nodeName": "string",    "sameCluster": true  },  "items": [    {      "address": "string",      "createdAt": "2019-08-24T14:15:22Z",      "gateway": true,      "handshakeReported": true,      "hub": true,      "id": "string",      "lastHandshakeAt": "2019-08-24T14:15:22Z",      "lastSeenAt": "2019-08-24T14:15:22Z",      "nodeName": "string",      "public": true,      "revokedAt": "2019-08-24T14:15:22Z",      "underlayAddress": "string"    }  ]}
DELETE/api/v1/clusters/{id}/mesh-peers/{peerId}

Authorization

AuthorizationBearer <token>

An API token, sent as Authorization: Bearer <token>. A token belongs to one organization and has the role it was created with, so it needs no X-Nebula-Organization header; if you send one, it must name the token's organization.

In: header

Path Parameters

id*string
peerId*string

Response Body

application/problem+json

curl -X DELETE "https://example.com/api/v1/clusters/string/mesh-peers/string"
Empty
GET/api/v1/environments/{id}/mesh-grants

Authorization

AuthorizationBearer <token>

An API token, sent as Authorization: Bearer <token>. A token belongs to one organization and has the role it was created with, so it needs no X-Nebula-Organization header; if you send one, it must name the token's organization.

In: header

Path Parameters

id*string

Response Body

application/json

application/problem+json

curl -X GET "https://example.com/api/v1/environments/string/mesh-grants"
[  {    "$schema": "https://example.com/MeshGrantBody.json",    "createdAt": "2019-08-24T14:15:22Z",    "direction": "string",    "id": "string",    "sameCluster": true,    "sourceEnvironmentId": "string",    "sourcePodCount": 0,    "status": "string",    "targetAddress": "string",    "targetEnvironmentId": "string",    "targetProcessId": "string",    "targetServiceId": "string"  }]
POST/api/v1/environments/{id}/mesh-grants

Authorization

AuthorizationBearer <token>

An API token, sent as Authorization: Bearer <token>. A token belongs to one organization and has the role it was created with, so it needs no X-Nebula-Organization header; if you send one, it must name the token's organization.

In: header

Path Parameters

id*string

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/problem+json

curl -X POST "https://example.com/api/v1/environments/string/mesh-grants" \  -H "Content-Type: application/json" \  -d '{    "processId": "string",    "serviceId": "string",    "sourceEnvironmentId": "string"  }'
{  "$schema": "https://example.com/MeshGrantBody.json",  "createdAt": "2019-08-24T14:15:22Z",  "direction": "string",  "id": "string",  "sameCluster": true,  "sourceEnvironmentId": "string",  "sourcePodCount": 0,  "status": "string",  "targetAddress": "string",  "targetEnvironmentId": "string",  "targetProcessId": "string",  "targetServiceId": "string"}
DELETE/api/v1/mesh-grants/{id}

Authorization

AuthorizationBearer <token>

An API token, sent as Authorization: Bearer <token>. A token belongs to one organization and has the role it was created with, so it needs no X-Nebula-Organization header; if you send one, it must name the token's organization.

In: header

Path Parameters

id*string

Response Body

application/problem+json

curl -X DELETE "https://example.com/api/v1/mesh-grants/string"
Empty