> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Preflight Ankra Cloud cluster

> Bearer PAT authentication; RBAC permission `clusters. RBAC permission `clusters.create`. Checks the create request against the account without creating anything: the credential authenticates, the zone offers compute, every plan and the template exist, an adopted network lives in the zone, and the counts are within bounds. Answers 404 while the organisation's `ankra_cloud_provider` feature flag is off.



## OpenAPI

````yaml https://platform.ankra.app/openapi.json post /api/v1/clusters/ankracloud/preflight
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
tags:
  - name: Organisation IAM
    description: >-
      Custom organisation roles and scoped role assignments for member and
      service-account identities.
  - name: Clusters
    description: Create, inspect and manage clusters, and the stacks deployed on them.
  - name: Managed Clusters
    description: Provider-managed control planes, driven through one common surface.
  - name: Imported Clusters
    description: Clusters that already existed and were connected to Ankra.
  - name: Cluster Access
    description: Kubeconfigs, service-account tokens and per-cluster access grants.
  - name: Kubernetes
    description: Read and act on the Kubernetes objects inside a cluster.
  - name: AWS Clusters
    description: >-
      Provision and manage self-managed k3s / kubeadm clusters on AWS EC2 in
      your own VPC.
  - name: Ankra Cloud Clusters
    description: >-
      Provision and manage self-managed kubeadm / k3s clusters on Ankra Cloud
      servers: a private network, a NAT router and a bastion per cluster.
  - name: DigitalOcean Clusters
    description: Provision and manage DigitalOcean Kubernetes clusters.
  - name: Hetzner Clusters
    description: Provision and manage Hetzner Kubernetes clusters.
  - name: OVH Clusters
    description: Provision and manage OVH Kubernetes clusters.
  - name: Scaleway Clusters
    description: Provision and manage Scaleway Kapsule clusters.
  - name: UpCloud Clusters
    description: Provision and manage UpCloud Kubernetes clusters.
  - name: Applications
    description: Deploy, configure and observe applications across the fleet.
  - name: Pipelines
    description: Pipeline definitions and the approval of the authority they declare.
  - name: Backups
    description: >-
      Backup vaults, restore points, protection posture and captures for stacks
      and application deployments; a completed capture is not a verified
      restore.
  - name: Stack Profiles
    description: Reusable stack definitions, their versions and sharing.
  - name: Services
    description: >-
      Versioned service packages and explicit sharing. Runtime admission is
      separate from publication.
  - name: Charts
    description: Browse the chart catalogue behind stacks and addons.
  - name: Helm
    description: Helm registries, credentials and the charts they expose.
  - name: Executions
    description: Long-running platform executions and their jobs.
  - name: Operations
    description: Cancel in-flight cluster operations and their jobs.
  - name: Chat
    description: Conversational sessions, plans and confirmable actions.
  - name: AI Management
    description: >-
      Customer agent lifecycle, authenticated identity and organisation
      automation controls.
  - name: AI Agent Runs
    description: Autonomous agent runs and their outcomes.
  - name: AI Tickets
    description: The AI ticket board, its sync connections and settings.
  - name: AI Playbooks
    description: Reusable playbooks the AI lanes execute.
  - name: AI Conditions
    description: Conditions that gate AI autonomy.
  - name: AI Remediation
    description: >-
      The organisation's auto-remediation policy: what the AI lanes may fix by
      themselves, and who approves the rest.
  - name: AI Engineering Handoffs
    description: Work the AI lanes escalate to a human engineer.
  - name: AI Environment
    description: The environment and base stacks AI demos deploy into.
  - name: Security
    description: Findings, advisories, SBOMs, compliance and posture.
  - name: Cost
    description: Cluster and fleet cost, rate cards and cost settings.
  - name: Decisions
    description: >-
      The decision ledger behind the Security and Cost queues: proposals a
      surface computed, the approve and set-aside decisions people took on them,
      and the receipts of running them.
  - name: Billing
    description: Subscription and spend caps.
  - name: Organisation
    description: Members, invitations, audit logs and organisation settings.
  - name: Account Tokens
    description: Personal access tokens for the API and CLI.
  - name: Credentials
    description: The shared credential store.
  - name: AWS Credentials
    description: >-
      AWS credentials: access keys or CloudFormation-onboarded STS roles for
      cost, EKS and self-managed provisioning.
  - name: Ankra Cloud Credentials
    description: >-
      Ankra Cloud API tokens, shared by the self-managed and managed Ankra Cloud
      lanes.
  - name: Azure Credentials
    description: Azure credentials and SSH keys.
  - name: DigitalOcean Credentials
    description: DigitalOcean credentials and SSH keys.
  - name: Hetzner Credentials
    description: Hetzner credentials and SSH keys.
  - name: OVH Credentials
    description: OVH credentials and SSH keys.
  - name: Scaleway Credentials
    description: Scaleway credentials.
  - name: UpCloud Credentials
    description: UpCloud credentials and SSH keys.
  - name: Data Source Credentials
    description: Credentials for metrics and log sources.
  - name: DNS Credentials
    description: Credentials for DNS providers.
  - name: Object Storage Buckets
    description: >-
      Buckets Ankra creates and manages on an organisation's own provider
      credentials.
  - name: DNS
    description: DNS zones and records, including custom organisation zones.
  - name: Cloudflare
    description: Cloudflare domains and the credentials behind them.
  - name: Variables
    description: Organisation- and cluster-scoped variables.
  - name: SOPS
    description: Encrypt and decrypt values with the organisation SOPS config.
  - name: Alerts
    description: Alert integrations and ingest credentials.
  - name: Notifications
    description: Notification routes and their delivery targets.
  - name: Support
    description: Support tickets.
  - name: AI Settings
    description: Organisation AI provider, model catalog and per-function model settings
paths:
  /api/v1/clusters/ankracloud/preflight:
    post:
      tags:
        - Ankra Cloud Clusters
      summary: Preflight Ankra Cloud cluster
      description: >-
        Bearer PAT authentication; RBAC permission `clusters. RBAC permission
        `clusters.create`. Checks the create request against the account without
        creating anything: the credential authenticates, the zone offers
        compute, every plan and the template exist, an adopted network lives in
        the zone, and the counts are within bounds. Answers 404 while the
        organisation's `ankra_cloud_provider` feature flag is off.
      operationId: preflight_ankracloud_cluster_pat
      parameters:
        - description: PAT organisation override.
          in: header
          name: x-ankra-organisation-id
          required: false
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateAnkraCloudClusterRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AnkraCloudPreflightResult'
          description: Successful response
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AnkraCloudCreateClusterResponse'
          description: Successful response
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Invalid request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Unauthenticated
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Permission or CSRF check failed
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Resource not found
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Conflicting or unsafe lifecycle state
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Request validation failed
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Provider or internal failure
      security:
        - BearerAuth: []
components:
  schemas:
    CreateAnkraCloudClusterRequest:
      example:
        bastion_allowed_ips:
          - 203.0.113.0/24
        bastion_plan: c1-2
        cni: cilium
        control_plane_count: 3
        control_plane_plan: c2-4
        credential_id: 11111111-2222-4333-8444-555555555555
        distribution: kubeadm
        name: ankra-prod
        network_ip_range: 10.42.0.0/20
        ssh_key_credential_id: 99999999-8888-4777-8666-555555555555
        template: debian-13
        worker_count: 2
        worker_plan: c4-8
        zone: de-fsn1
      properties:
        bastion_allowed_ips:
          description: >-
            IPv4/IPv6 addresses or CIDRs allowed to SSH to the bastion; empty
            allows any source.
          items:
            type: string
          type: array
        bastion_plan:
          type: string
        bastion_port:
          default: 22
          description: >-
            Accepted for contract symmetry with the managed-gateway providers
            and ignored: the bastion listens on 22.
          type: integer
        cni:
          default: cilium
          description: kubeadm supports only cilium on Ankra Cloud.
          enum:
            - flannel
            - calico
            - cilium
          type: string
        cni_features:
          $ref: '#/components/schemas/AnkraCloudCNIFeatures'
        control_plane_count:
          default: 1
          maximum: 9
          minimum: 1
          type: integer
        control_plane_plan:
          type: string
        credential_id:
          type: string
          format: uuid
        criticality:
          anyOf:
            - type: string
            - type: 'null'
        description:
          anyOf:
            - type: string
            - type: 'null'
        distribution:
          type: string
          enum:
            - k3s
            - kubeadm
          default: kubeadm
        environment:
          anyOf:
            - type: string
            - type: 'null'
        etcd_node_count:
          type: integer
          default: 3
        etcd_plan:
          default: ''
          description: Required for an external etcd topology.
          type: string
        etcd_topology:
          type: string
          enum:
            - stacked
            - external
          default: stacked
        external_cloud_provider:
          const: true
          default: true
          type: boolean
        gitops_branch:
          type: string
          default: master
        gitops_provider:
          type: string
          enum:
            - github
            - bitbucket_cloud
          default: github
          description: >-
            GitOps provider of the repository the cluster is bootstrapped onto.
            Omitted is github, where gitops_repository is owner/name.
            bitbucket_cloud names the repository by gitops_workspace and
            gitops_repo_slug (or gitops_repository as workspace/repo_slug) and
            binds it as a Bitbucket Cloud repository.
        gitops_workspace:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Bitbucket Cloud workspace of the GitOps repository. Only with
            gitops_provider bitbucket_cloud; provided together with
            gitops_repo_slug.
        gitops_repo_slug:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Bitbucket Cloud repository slug of the GitOps repository. Only with
            gitops_provider bitbucket_cloud; provided together with
            gitops_workspace.
        gitops_credential_name:
          default: ''
          type: string
        gitops_repository:
          default: ''
          type: string
        include_dns:
          type: boolean
          default: true
        include_networking:
          type: boolean
          default: true
        k3s_disabled_components:
          anyOf:
            - type: array
              items:
                type: string
            - type: 'null'
        kubernetes_version:
          anyOf:
            - type: string
            - type: 'null'
        name:
          type: string
        network_ip_range:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            RFC 1918 CIDR (/16 through /29) of the private network Ankra
            creates; omitted derives one per cluster.
        node_groups:
          items:
            $ref: '#/components/schemas/AnkraCloudCreateNodeGroupRequest'
          type: array
        private_network_id:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Adopts an existing private network in the zone; mutually exclusive
            with network_ip_range. An adopted network is never deleted by the
            cluster.
        retention_policy:
          type: string
          enum:
            - delete
            - retain
          default: retain
        runtime_credential_id:
          anyOf:
            - type: string
              format: uuid
            - type: 'null'
          description: >-
            Credential the running cluster's cloud-controller-manager and CSI
            use; omitted reuses credential_id.
        ssh_key_credential_id:
          type: string
          format: uuid
        template:
          default: debian-13
          description: Public OS template id (GET /clusters/ankracloud/templates).
          type: string
        worker_count:
          default: 1
          maximum: 100
          minimum: 0
          type: integer
        worker_plan:
          default: ''
          description: >-
            Required when worker_count is above zero and no node_groups are
            given.
          type: string
        zone:
          description: >-
            Ankra Cloud zone (GET /clusters/ankracloud/zones); every server of
            the cluster is placed there.
          type: string
      required:
        - name
        - credential_id
        - ssh_key_credential_id
        - zone
        - bastion_plan
        - control_plane_plan
      type: object
    AnkraCloudPreflightResult:
      properties:
        can_proceed:
          type: boolean
        items:
          items:
            $ref: '#/components/schemas/AnkraCloudPreflightItem'
          type: array
      required:
        - items
        - can_proceed
      type: object
    AnkraCloudCreateClusterResponse:
      example:
        cluster_id: 11111111-2222-4333-8444-555555555555
        name: ankra-prod
      properties:
        cluster_id:
          type: string
          format: uuid
        name:
          type: string
      required:
        - cluster_id
        - name
      type: object
    ContractDetailError:
      example:
        detail: Cluster not found
      properties:
        detail:
          oneOf:
            - type: string
            - additionalProperties: true
              properties: {}
              type: object
      required:
        - detail
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    AnkraCloudCNIFeatures:
      properties:
        ebpf_dataplane:
          default: false
          type: boolean
        hubble:
          default: false
          type: boolean
        kube_proxy_replacement:
          default: false
          type: boolean
        wireguard_encryption:
          default: false
          type: boolean
      type: object
    AnkraCloudCreateNodeGroupRequest:
      properties:
        autoscaling:
          anyOf:
            - properties:
                enabled:
                  type: boolean
                max_count:
                  type: integer
                min_count:
                  type: integer
              required:
                - enabled
                - min_count
                - max_count
              type: object
            - type: 'null'
        count:
          default: 1
          maximum: 100
          minimum: 0
          type: integer
        instance_type:
          type: string
        labels:
          additionalProperties:
            type: string
          type: object
        name:
          type: string
        taints:
          items:
            $ref: '#/components/schemas/AnkraCloudNodeTaint'
          type: array
      required:
        - name
        - instance_type
      type: object
    AnkraCloudPreflightItem:
      properties:
        check:
          type: string
        message:
          type: string
        status:
          enum:
            - pass
            - warn
            - fail
          type: string
      required:
        - check
        - status
        - message
      type: object
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
    AnkraCloudNodeTaint:
      properties:
        effect:
          enum:
            - NoSchedule
            - PreferNoSchedule
            - NoExecute
          type: string
        key:
          type: string
        value:
          default: ''
          type: string
      required:
        - key
        - effect
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: PAT
      scheme: bearer
      type: http

````