import requests
url = "https://platform.ankra.app/org/applications/{application_id}/env-secrets/apply"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://platform.ankra.app/org/applications/{application_id}/env-secrets/apply', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request POST \
--url https://platform.ankra.app/org/applications/{application_id}/env-secrets/apply \
--header 'Authorization: Bearer <token>'{
"revision": "<string>",
"applied_count": 123,
"skipped_count": 123,
"failed_count": 123,
"deployments": [
{
"installation_id": "<string>",
"cluster_id": "<string>",
"namespace": "<string>",
"status": "applied",
"message": "<string>",
"rolled_workloads": 123
}
]
}{
"detail": "<string>"
}{
"detail": "<string>"
}{
"detail": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}{
"detail": "<string>"
}Apply application environment secrets (browser session)
Apply the application’s stored environment secrets to what is already running: re-seal them into the Secrets the manifests read on every deployment and roll the workloads that read them. An application whose last key has been cleared applies too, and the apply then removes the sealed Secret from the deployment’s stack and rolls the workloads off those values - without it, every reconcile put the deleted values back. The values only reach a running workload at deploy time otherwise, so this is the explicit one-click close of that gap - it is never triggered implicitly by setting a value. It takes no body (the values it applies are the ones already stored) and returns none. The deploy parameters of each deployment are left untouched: only the environment-secret manifest and the pod templates that read it are written. A browser session twin is mounted at the same path without the /api/v1 prefix (cookie authentication plus the X-Ankra-CSRF double-submit header). With environment_id, resolve or modify only that environment; deletion suppresses a shared default locally, and apply never changes another target. Without it, existing shared catalogue behaviour is retained; all-target apply still preserves environment overrides.
import requests
url = "https://platform.ankra.app/org/applications/{application_id}/env-secrets/apply"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://platform.ankra.app/org/applications/{application_id}/env-secrets/apply', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request POST \
--url https://platform.ankra.app/org/applications/{application_id}/env-secrets/apply \
--header 'Authorization: Bearer <token>'{
"revision": "<string>",
"applied_count": 123,
"skipped_count": 123,
"failed_count": 123,
"deployments": [
{
"installation_id": "<string>",
"cluster_id": "<string>",
"namespace": "<string>",
"status": "applied",
"message": "<string>",
"rolled_workloads": 123
}
]
}{
"detail": "<string>"
}{
"detail": "<string>"
}{
"detail": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}{
"detail": "<string>"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Query Parameters
Select an owned canonical application environment, including a planned environment. A legacy cluster ID is accepted only when it identifies one complete environment, or an unassigned legacy cluster. Mixed or partial aliases return 409; refresh and select the canonical ID. Empty or repeated values are refused. Omit only for shared catalogue management or application-wide apply.
Response
Successful Response
The result of re-sealing an application's stored environment secrets into every deployment of it. No stored value appears in this model - the surface has no route that returns one.
Selected environment effective revision, or shared-default revision for legacy application-wide apply. Each target resolves its own overrides.
Show child attributes
Show child attributes