> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Preview restoring an application deployment

> Answers what restoring this deployment in place from this restore point would do if it were confirmed now, without doing any of it: the steps in order with the volume claims they remove, the namespaces whose objects are restored, whether a safety copy of the live stack is taken first, every reason the restore would be refused, and whether the stack has drifted. It opens no run, mints no restore point and writes nothing to the stack. The stack is resolved from the application's own records; a restore point captured from another stack or cluster is not found here. Requires the backups rollout flag and backups.read.



## OpenAPI

````yaml https://platform.ankra.app/openapi.json get /api/v1/org/applications/{application_id}/deployments/{deployment_id}/restore-points/{restore_point_id}/restore-plan
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
tags:
  - name: Organisation IAM
    description: >-
      Custom organisation roles and scoped role assignments for member and
      service-account identities.
  - name: Clusters
    description: Create, inspect and manage clusters, and the stacks deployed on them.
  - name: Managed Clusters
    description: Provider-managed control planes, driven through one common surface.
  - name: Imported Clusters
    description: Clusters that already existed and were connected to Ankra.
  - name: Cluster Access
    description: Kubeconfigs, service-account tokens and per-cluster access grants.
  - name: Kubernetes
    description: Read and act on the Kubernetes objects inside a cluster.
  - name: AWS Clusters
    description: >-
      Provision and manage self-managed k3s / kubeadm clusters on AWS EC2 in
      your own VPC.
  - name: Ankra Cloud Clusters
    description: >-
      Provision and manage self-managed kubeadm / k3s clusters on Ankra Cloud
      servers: a private network, a NAT router and a bastion per cluster.
  - name: DigitalOcean Clusters
    description: Provision and manage DigitalOcean Kubernetes clusters.
  - name: Hetzner Clusters
    description: Provision and manage Hetzner Kubernetes clusters.
  - name: OVH Clusters
    description: Provision and manage OVH Kubernetes clusters.
  - name: Scaleway Clusters
    description: Provision and manage Scaleway Kapsule clusters.
  - name: UpCloud Clusters
    description: Provision and manage UpCloud Kubernetes clusters.
  - name: Applications
    description: Deploy, configure and observe applications across the fleet.
  - name: Pipelines
    description: >-
      Pipeline definitions, the approval of the authority they declare, and the
      caches pipelines keep between runs.
  - name: Workspaces
    description: >-
      Personal workspaces on the organisation's CI pool where a repository's
      heavy commands run, and the repository profiles they are built from.
  - name: Deploy Targets
    description: >-
      Environments, the hosts registered to receive deployments, and the
      releases deployed to them.
  - name: Backups
    description: >-
      Backup vaults, restore points, protection posture and captures for stacks
      and application deployments; a completed capture is not a verified
      restore.
  - name: Stack Profiles
    description: Reusable stack definitions, their versions and sharing.
  - name: Services
    description: >-
      Versioned service packages and explicit sharing. Runtime admission is
      separate from publication.
  - name: Charts
    description: Browse the chart catalogue behind stacks and addons.
  - name: Helm
    description: Helm registries, credentials and the charts they expose.
  - name: Executions
    description: Long-running platform executions and their jobs.
  - name: Operations
    description: Cancel in-flight cluster operations and their jobs.
  - name: Chat
    description: Conversational sessions, plans and confirmable actions.
  - name: AI Management
    description: >-
      Customer agent lifecycle, authenticated identity and organisation
      automation controls.
  - name: AI Agent Runs
    description: Autonomous agent runs and their outcomes.
  - name: AI Tickets
    description: The AI ticket board, its sync connections and settings.
  - name: AI Playbooks
    description: Reusable playbooks the AI lanes execute.
  - name: AI Conditions
    description: Conditions that gate AI autonomy.
  - name: AI Remediation
    description: >-
      The organisation's auto-remediation policy: what the AI lanes may fix by
      themselves, and who approves the rest.
  - name: AI Engineering Handoffs
    description: Work the AI lanes escalate to a human engineer.
  - name: AI Environment
    description: The environment and base stacks AI demos deploy into.
  - name: Security
    description: Findings, advisories, SBOMs, compliance and posture.
  - name: Cost
    description: Cluster and fleet cost, rate cards and cost settings.
  - name: Decisions
    description: >-
      The decision ledger behind the Security and Cost queues: proposals a
      surface computed, the approve and set-aside decisions people took on them,
      and the receipts of running them.
  - name: Usage
    description: >-
      What your organisation used of Ankra - vCPU-hours, playgrounds, managed
      services, hosted logs and metrics, and AI - per meter and period, with how
      completely it was measured and whether a published rate applies.
  - name: Billing
    description: Subscription and spend caps.
  - name: Organisation
    description: Members, invitations, audit logs and organisation settings.
  - name: Account
    description: >-
      Your own account: the contact email Ankra mails when it differs from your
      sign-in address.
  - name: Account Tokens
    description: Personal access tokens for the API and CLI.
  - name: Credentials
    description: The shared credential store.
  - name: AWS Credentials
    description: >-
      AWS credentials: access keys or CloudFormation-onboarded STS roles for
      cost, EKS and self-managed provisioning.
  - name: Ankra Cloud Credentials
    description: >-
      Ankra Cloud API tokens, shared by the self-managed and managed Ankra Cloud
      lanes.
  - name: Azure Credentials
    description: Azure credentials and SSH keys.
  - name: DigitalOcean Credentials
    description: DigitalOcean credentials and SSH keys.
  - name: Hetzner Credentials
    description: Hetzner credentials and SSH keys.
  - name: OVH Credentials
    description: OVH credentials and SSH keys.
  - name: Scaleway Credentials
    description: Scaleway credentials.
  - name: UpCloud Credentials
    description: UpCloud credentials and SSH keys.
  - name: Data Source Credentials
    description: Credentials for metrics and log sources.
  - name: DNS Credentials
    description: Credentials for DNS providers.
  - name: Object Storage Buckets
    description: >-
      Buckets Ankra creates and manages on an organisation's own provider
      credentials.
  - name: DNS
    description: DNS zones and records, including custom organisation zones.
  - name: Cloudflare
    description: Cloudflare domains and the credentials behind them.
  - name: Avura
    description: >-
      The linked Avura organization, the domains it shares with Ankra Platform,
      and their DNS records.
  - name: Variables
    description: Organisation- and cluster-scoped variables.
  - name: SOPS
    description: Encrypt and decrypt values with the organisation SOPS config.
  - name: Alerts
    description: Alert integrations and ingest credentials.
  - name: Notifications
    description: Notification routes and their delivery targets.
  - name: Support
    description: Support tickets.
  - name: AI Settings
    description: Organisation AI provider, model catalog and per-function model settings
paths:
  /api/v1/org/applications/{application_id}/deployments/{deployment_id}/restore-points/{restore_point_id}/restore-plan:
    get:
      tags:
        - Backups
      summary: Preview restoring an application deployment
      description: >-
        Answers what restoring this deployment in place from this restore point
        would do if it were confirmed now, without doing any of it: the steps in
        order with the volume claims they remove, the namespaces whose objects
        are restored, whether a safety copy of the live stack is taken first,
        every reason the restore would be refused, and whether the stack has
        drifted. It opens no run, mints no restore point and writes nothing to
        the stack. The stack is resolved from the application's own records; a
        restore point captured from another stack or cluster is not found here.
        Requires the backups rollout flag and backups.read.
      operationId: getApplicationRestorePlanToken
      parameters:
        - in: path
          name: application_id
          required: true
          schema:
            type: string
        - name: deployment_id
          in: path
          required: true
          description: The deployment cluster id.
          schema:
            type: string
            format: uuid
        - name: restore_point_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
        - name: force
          in: query
          required: false
          description: >-
            Plan the forced restore: drift is then reported and no longer
            refused.
          schema:
            default: false
            type: boolean
      responses:
        '200':
          description: >-
            The plan. A plan with refusals is still a 200: the refusals are its
            content.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationRestorePlan'
        '401':
          description: Not authenticated.
        '403':
          description: backups.read is not held, or the backups rollout is off.
        '404':
          description: Unknown application, deployment or restore point.
        '409':
          description: The deployment has not created its stack yet.
        '422':
          description: A path id is not a UUID, or force is not a boolean.
        '500':
          description: Internal error.
      security:
        - BearerAuth: []
components:
  schemas:
    ApplicationRestorePlan:
      type: object
      description: >-
        What restoring one application deployment in place from one restore
        point would do if it were confirmed now. Nothing in it has happened. It
        is produced by the same assessment the restore runs, so a refusal listed
        here is the refusal the restore answers with. Three fields say whether
        the others were established: when effects_known is false, steps,
        replaces and restores_namespace_objects are empty because the plan
        stopped before the restore point could be read, not because the restore
        touches nothing; when drift_known is false, drift was not compared; and
        safety_copy unknown means the copy was not planned.
      required:
        - restore_point_id
        - stack_name
        - cluster_id
        - cluster_name
        - mode
        - force
        - effects_known
        - steps
        - replaces
        - restores_namespace_objects
        - safety_copy
        - refusals
        - drift
        - drift_known
        - drift_details
        - not_carried
        - warnings
      properties:
        restore_point_id:
          type: string
          format: uuid
        stack_name:
          type: string
          description: >-
            The stack this deployment runs as, resolved on the server. It is the
            value the restore's confirm must match.
        cluster_id:
          type: string
          format: uuid
        cluster_name:
          type: string
        mode:
          type: string
          enum:
            - in_place
        force:
          type: boolean
          description: Whether this is the plan of a forced restore.
        effects_known:
          type: boolean
        steps:
          type: array
          items:
            type: string
          description: >-
            The sequence the restore performs, in order, naming the claims it
            removes. The restore's 202 repeats these lines as sequence.
        replaces:
          type: array
          description: >-
            Every volume claim the restore deletes before it writes the copy
            back.
          items:
            type: object
            required:
              - namespace
              - claim
            properties:
              namespace:
                type: string
              claim:
                type: string
        restores_namespace_objects:
          type: array
          items:
            type: string
          description: >-
            Namespaces whose Kubernetes objects the restore puts back as well:
            the volume engine restores a whole namespace, not only the claims
            named.
        safety_copy:
          type: string
          enum:
            - will_take
            - nothing_to_keep
            - unavailable
            - unknown
          description: >-
            will_take: the live stack is captured first and the restore is
            refused if that capture cannot be taken. nothing_to_keep: the live
            stack holds nothing a capture can carry and the restore removes
            nothing. unavailable: the live stack cannot be captured, so the
            restore is refused. unknown: the plan stopped before the copy could
            be planned.
        refusals:
          type: array
          description: >-
            Why a restore confirmed now would be refused, in the order the
            restore meets them; the first is the one the restore answers with.
            Empty means it would be accepted.
          items:
            type: object
            required:
              - code
              - message
              - force_overrides
            properties:
              code:
                type: string
                enum:
                  - mode_unsupported
                  - restore_point_not_complete
                  - not_restorable_in_place
                  - confirmation_mismatch
                  - engine_unsupported
                  - nothing_to_restore
                  - unnamed_claims
                  - cluster_unavailable
                  - operations_blocked
                  - agent_missing
                  - foreign_claims
                  - stack_drift
                  - safety_copy_unavailable
                  - stack_not_found
              message:
                type: string
                description: >-
                  The sentence the restore route answers the same refusal with
                  as detail.
              force_overrides:
                type: boolean
                description: >-
                  True only for stack_drift, the one refusal a forced restore
                  goes past.
        drift:
          type: boolean
        drift_known:
          type: boolean
        drift_details:
          type: array
          items:
            type: string
        not_carried:
          type: array
          description: >-
            What the restore point does not contain, and so what the restore
            will not bring back.
          items:
            type: object
            required:
              - kind
              - name
              - reason
            properties:
              kind:
                type: string
              name:
                type: string
              reason:
                type: string
              remedy:
                type: string
        warnings:
          type: array
          items:
            type: string
  securitySchemes:
    BearerAuth:
      bearerFormat: PAT
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.