> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Apply Application Env Secrets

> Apply the application's stored environment secrets to what is already running: re-seal them into the Secrets the manifests read on every deployment and roll the workloads that read them. An application whose last key has been cleared applies too, and the apply then removes the sealed Secret from the deployment's stack and rolls the workloads off those values - without it, every reconcile put the deleted values back. The values only reach a running workload at deploy time otherwise, so this is the explicit one-click close of that gap - it is never triggered implicitly by setting a value. It takes no body (the values it applies are the ones already stored) and returns none. The deploy parameters of each deployment are left untouched: only the environment-secret manifest and the pod templates that read it are written. A browser session twin is mounted at the same path without the /api/v1 prefix (cookie authentication plus the X-Ankra-CSRF double-submit header).



## OpenAPI

````yaml https://platform.ankra.app/openapi.json post /api/v1/org/applications/{application_id}/env-secrets/apply
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
tags:
  - name: Clusters
    description: Create, inspect and manage clusters, and the stacks deployed on them.
  - name: Managed Clusters
    description: Provider-managed control planes, driven through one common surface.
  - name: Imported Clusters
    description: Clusters that already existed and were connected to Ankra.
  - name: Cluster Access
    description: Kubeconfigs, service-account tokens and per-cluster access grants.
  - name: Kubernetes
    description: Read and act on the Kubernetes objects inside a cluster.
  - name: DigitalOcean Clusters
    description: Provision and manage DigitalOcean Kubernetes clusters.
  - name: Hetzner Clusters
    description: Provision and manage Hetzner Kubernetes clusters.
  - name: OVH Clusters
    description: Provision and manage OVH Kubernetes clusters.
  - name: Scaleway Clusters
    description: Provision and manage Scaleway Kapsule clusters.
  - name: UpCloud Clusters
    description: Provision and manage UpCloud Kubernetes clusters.
  - name: Applications
    description: Deploy, configure and observe applications across the fleet.
  - name: Stack Profiles
    description: Reusable stack definitions, their versions and sharing.
  - name: Charts
    description: Browse the chart catalogue behind stacks and addons.
  - name: Helm
    description: Helm registries, credentials and the charts they expose.
  - name: Executions
    description: Long-running platform executions and their jobs.
  - name: Operations
    description: Cancel in-flight cluster operations and their jobs.
  - name: Chat
    description: Conversational sessions, plans and confirmable actions.
  - name: AI Agent Runs
    description: Autonomous agent runs and their outcomes.
  - name: AI Tickets
    description: The AI ticket board, its sync connections and settings.
  - name: AI Playbooks
    description: Reusable playbooks the AI lanes execute.
  - name: AI Conditions
    description: Conditions that gate AI autonomy.
  - name: AI Engineering Handoffs
    description: Work the AI lanes escalate to a human engineer.
  - name: AI Environment
    description: The environment and base stacks AI demos deploy into.
  - name: Security
    description: Findings, advisories, SBOMs, compliance and posture.
  - name: Cost
    description: Cluster and fleet cost, rate cards and cost settings.
  - name: Billing
    description: Subscription and spend caps.
  - name: Organisation
    description: Members, invitations, audit logs and organisation settings.
  - name: Account Tokens
    description: Personal access tokens for the API and CLI.
  - name: Credentials
    description: The shared credential store.
  - name: Azure Credentials
    description: Azure credentials and SSH keys.
  - name: DigitalOcean Credentials
    description: DigitalOcean credentials and SSH keys.
  - name: Hetzner Credentials
    description: Hetzner credentials and SSH keys.
  - name: OVH Credentials
    description: OVH credentials and SSH keys.
  - name: Scaleway Credentials
    description: Scaleway credentials.
  - name: UpCloud Credentials
    description: UpCloud credentials and SSH keys.
  - name: Data Source Credentials
    description: Credentials for metrics and log sources.
  - name: DNS Credentials
    description: Credentials for DNS providers.
  - name: DNS
    description: DNS zones and records, including custom organisation zones.
  - name: Cloudflare
    description: Cloudflare domains and the credentials behind them.
  - name: Variables
    description: Organisation- and cluster-scoped variables.
  - name: SOPS
    description: Encrypt and decrypt values with the organisation SOPS config.
  - name: Alerts
    description: Alert integrations and ingest credentials.
  - name: Notifications
    description: Notification routes and their delivery targets.
  - name: Support
    description: Support tickets.
paths:
  /api/v1/org/applications/{application_id}/env-secrets/apply:
    post:
      tags:
        - Applications
      summary: Apply Application Env Secrets
      description: >-
        Apply the application's stored environment secrets to what is already
        running: re-seal them into the Secrets the manifests read on every
        deployment and roll the workloads that read them. An application whose
        last key has been cleared applies too, and the apply then removes the
        sealed Secret from the deployment's stack and rolls the workloads off
        those values - without it, every reconcile put the deleted values back.
        The values only reach a running workload at deploy time otherwise, so
        this is the explicit one-click close of that gap - it is never triggered
        implicitly by setting a value. It takes no body (the values it applies
        are the ones already stored) and returns none. The deploy parameters of
        each deployment are left untouched: only the environment-secret manifest
        and the pod templates that read it are written. A browser session twin
        is mounted at the same path without the /api/v1 prefix (cookie
        authentication plus the X-Ankra-CSRF double-submit header).
      operationId: >-
        apply_application_env_secrets_api_v1_org_applications__application_id__env_secrets_apply_post
      parameters:
        - in: path
          name: application_id
          required: true
          schema:
            type: string
            title: Application Id
        - in: header
          name: authorization
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: Authorization
        - in: header
          name: x-ankra-organisation-id
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: X-Ankra-Organisation-Id
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplyApplicationEnvSecretsResponse'
          description: Successful Response
        '401':
          description: Unauthorized
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DemoDetailError'
          description: >-
            The member may not deploy this application, or (browser twin only)
            the CSRF check failed
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DemoDetailError'
          description: Not found ("Application not found")
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DemoDetailError'
          description: >-
            Nothing to apply to: the application is not deployed anywhere, every
            deployment of it is being removed, the organisation has no enabled
            SOPS configuration to seal the values with, or Ankra could not work
            out which Kubernetes Secret they belong in. An application with no
            environment secrets set is NOT refused - the apply removes the
            sealed Secret instead
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Validation Error
        '503':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DemoDetailError'
          description: >-
            The secret store, the encryptor or the stack-write lane is not
            available on this deployment of the platform
components:
  schemas:
    ApplyApplicationEnvSecretsResponse:
      description: >-
        The result of re-sealing an application's stored environment secrets
        into every deployment of it. No stored value appears in this model - the
        surface has no route that returns one.
      properties:
        revision:
          description: The catalogue revision this apply sealed.
          title: Revision
          type: string
        applied_count:
          title: Applied Count
          type: integer
        skipped_count:
          title: Skipped Count
          type: integer
        failed_count:
          title: Failed Count
          type: integer
        deployments:
          items:
            $ref: '#/components/schemas/ApplyApplicationEnvSecretOutcome'
          title: Deployments
          type: array
      required:
        - revision
        - applied_count
        - skipped_count
        - failed_count
        - deployments
      title: ApplyApplicationEnvSecretsResponse
      type: object
    DemoDetailError:
      description: >-
        The FastAPI-style detail envelope the demo routes use for
        400/403/404/409/502 responses.
      properties:
        detail:
          type: string
      required:
        - detail
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    ApplyApplicationEnvSecretOutcome:
      description: What one apply did to one deployment.
      properties:
        installation_id:
          title: Installation Id
          type: string
        cluster_id:
          type: string
          title: Cluster Id
        namespace:
          title: Namespace
          type: string
        status:
          description: >-
            "applied" - the deployment's stack now carries the current values,
            and the cluster reconcile rolls the stamped workloads onto them.
            "skipped" - a deploy of it is already running and seals the same
            values itself. "failed" - the apply could not reach it; see message.
          enum:
            - applied
            - skipped
            - failed
          title: Status
          type: string
        message:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            What there is to say about this deployment: the reason for a skip or
            a failure, or - on an apply that landed but rolled nothing - why.
            Never carries a stored value.
          title: Message
        rolled_workloads:
          description: >-
            How many pod templates this apply stamped, which is how many
            workloads Kubernetes restarts onto the new values. Zero on a landed
            apply means every workload already carried this revision, no
            workload reads the Secret, or the deployment has no rendered
            manifest to check; the last two say so in message.
          title: Rolled Workloads
          type: integer
      required:
        - installation_id
        - cluster_id
        - namespace
        - status
        - message
        - rolled_workloads
      title: ApplyApplicationEnvSecretOutcome
      type: object
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object

````