> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Prepare a managed-service retirement review

> Requires the applications rollout flag, applications.deploy, and on the service cluster clusters.operate, stacks.delete and clusters.read, plus clusters.read on every consumer cluster, all intersected with live token scopes. Resolves, on the primary database, what retiring the instance removes and keeps - its stack found by resource id with every member and the namespace it deploys into, the consumers it is disconnected from, the shared operators it keeps and what happens to its data - and stores an actor-bound plan with a digest and a ten-minute expiry. Nothing on the cluster changes. Refused while the installation runs, while another retirement runs, for another generation, for a disconnect set that is not exactly the service's consumers, for a stack changed outside Services, and without the data-loss acknowledgement. An actor may hold at most 10 open retirements and an organisation 50.



## OpenAPI

````yaml https://platform.ankra.app/openapi.json post /api/v1/org/service-admission/instances/{instance_id}/retirements
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
tags:
  - name: Organisation IAM
    description: >-
      Custom organisation roles and scoped role assignments for member and
      service-account identities.
  - name: Clusters
    description: Create, inspect and manage clusters, and the stacks deployed on them.
  - name: Managed Clusters
    description: Provider-managed control planes, driven through one common surface.
  - name: Imported Clusters
    description: Clusters that already existed and were connected to Ankra.
  - name: Cluster Access
    description: Kubeconfigs, service-account tokens and per-cluster access grants.
  - name: Kubernetes
    description: Read and act on the Kubernetes objects inside a cluster.
  - name: AWS Clusters
    description: >-
      Provision and manage self-managed k3s / kubeadm clusters on AWS EC2 in
      your own VPC.
  - name: Ankra Cloud Clusters
    description: >-
      Provision and manage self-managed kubeadm / k3s clusters on Ankra Cloud
      servers: a private network, a NAT router and a bastion per cluster.
  - name: DigitalOcean Clusters
    description: Provision and manage DigitalOcean Kubernetes clusters.
  - name: Hetzner Clusters
    description: Provision and manage Hetzner Kubernetes clusters.
  - name: OVH Clusters
    description: Provision and manage OVH Kubernetes clusters.
  - name: Scaleway Clusters
    description: Provision and manage Scaleway Kapsule clusters.
  - name: UpCloud Clusters
    description: Provision and manage UpCloud Kubernetes clusters.
  - name: Applications
    description: Deploy, configure and observe applications across the fleet.
  - name: Pipelines
    description: Pipeline definitions and the approval of the authority they declare.
  - name: Backups
    description: >-
      Backup vaults, restore points, protection posture and captures for stacks
      and application deployments; a completed capture is not a verified
      restore.
  - name: Stack Profiles
    description: Reusable stack definitions, their versions and sharing.
  - name: Services
    description: >-
      Versioned service packages and explicit sharing. Runtime admission is
      separate from publication.
  - name: Charts
    description: Browse the chart catalogue behind stacks and addons.
  - name: Helm
    description: Helm registries, credentials and the charts they expose.
  - name: Executions
    description: Long-running platform executions and their jobs.
  - name: Operations
    description: Cancel in-flight cluster operations and their jobs.
  - name: Chat
    description: Conversational sessions, plans and confirmable actions.
  - name: AI Management
    description: >-
      Customer agent lifecycle, authenticated identity and organisation
      automation controls.
  - name: AI Agent Runs
    description: Autonomous agent runs and their outcomes.
  - name: AI Tickets
    description: The AI ticket board, its sync connections and settings.
  - name: AI Playbooks
    description: Reusable playbooks the AI lanes execute.
  - name: AI Conditions
    description: Conditions that gate AI autonomy.
  - name: AI Remediation
    description: >-
      The organisation's auto-remediation policy: what the AI lanes may fix by
      themselves, and who approves the rest.
  - name: AI Engineering Handoffs
    description: Work the AI lanes escalate to a human engineer.
  - name: AI Environment
    description: The environment and base stacks AI demos deploy into.
  - name: Security
    description: Findings, advisories, SBOMs, compliance and posture.
  - name: Cost
    description: Cluster and fleet cost, rate cards and cost settings.
  - name: Decisions
    description: >-
      The decision ledger behind the Security and Cost queues: proposals a
      surface computed, the approve and set-aside decisions people took on them,
      and the receipts of running them.
  - name: Billing
    description: Subscription and spend caps.
  - name: Organisation
    description: Members, invitations, audit logs and organisation settings.
  - name: Account Tokens
    description: Personal access tokens for the API and CLI.
  - name: Credentials
    description: The shared credential store.
  - name: AWS Credentials
    description: >-
      AWS credentials: access keys or CloudFormation-onboarded STS roles for
      cost, EKS and self-managed provisioning.
  - name: Ankra Cloud Credentials
    description: >-
      Ankra Cloud API tokens, shared by the self-managed and managed Ankra Cloud
      lanes.
  - name: Azure Credentials
    description: Azure credentials and SSH keys.
  - name: DigitalOcean Credentials
    description: DigitalOcean credentials and SSH keys.
  - name: Hetzner Credentials
    description: Hetzner credentials and SSH keys.
  - name: OVH Credentials
    description: OVH credentials and SSH keys.
  - name: Scaleway Credentials
    description: Scaleway credentials.
  - name: UpCloud Credentials
    description: UpCloud credentials and SSH keys.
  - name: Data Source Credentials
    description: Credentials for metrics and log sources.
  - name: DNS Credentials
    description: Credentials for DNS providers.
  - name: Object Storage Buckets
    description: >-
      Buckets Ankra creates and manages on an organisation's own provider
      credentials.
  - name: DNS
    description: DNS zones and records, including custom organisation zones.
  - name: Cloudflare
    description: Cloudflare domains and the credentials behind them.
  - name: Avura
    description: >-
      The linked Avura organization, the domains it shares with Ankra Platform,
      and their DNS records.
  - name: Variables
    description: Organisation- and cluster-scoped variables.
  - name: SOPS
    description: Encrypt and decrypt values with the organisation SOPS config.
  - name: Alerts
    description: Alert integrations and ingest credentials.
  - name: Notifications
    description: Notification routes and their delivery targets.
  - name: Support
    description: Support tickets.
  - name: AI Settings
    description: Organisation AI provider, model catalog and per-function model settings
paths:
  /api/v1/org/service-admission/instances/{instance_id}/retirements:
    post:
      tags:
        - Services
      summary: Prepare a managed-service retirement review
      description: >-
        Requires the applications rollout flag, applications.deploy, and on the
        service cluster clusters.operate, stacks.delete and clusters.read, plus
        clusters.read on every consumer cluster, all intersected with live token
        scopes. Resolves, on the primary database, what retiring the instance
        removes and keeps - its stack found by resource id with every member and
        the namespace it deploys into, the consumers it is disconnected from,
        the shared operators it keeps and what happens to its data - and stores
        an actor-bound plan with a digest and a ten-minute expiry. Nothing on
        the cluster changes. Refused while the installation runs, while another
        retirement runs, for another generation, for a disconnect set that is
        not exactly the service's consumers, for a stack changed outside
        Services, and without the data-loss acknowledgement. An actor may hold
        at most 10 open retirements and an organisation 50.
      operationId: prepareServiceRetirementToken
      parameters:
        - name: instance_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ServiceRetirementRequest'
      responses:
        '200':
          description: The stored retirement review, its plan and digest.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceRetirement'
        '400':
          description: Bearer token not provided or invalid authorization header
        '401':
          description: Authentication required
        '403':
          description: Insufficient permission or missing browser CSRF
        '404':
          description: Not accessible, absent, or rollout disabled
        '409':
          description: >-
            The retirement was refused: the service is installing, already
            retiring or retired, changed generation, its stack or consumers
            changed, the digest is stale, or the review expired
        '422':
          description: Invalid or ambiguous request, or the data loss was not acknowledged
        '500':
          description: Internal error
        '503':
          description: Rollout availability could not be verified
      security:
        - BearerAuth: []
components:
  schemas:
    ServiceRetirementRequest:
      type: object
      additionalProperties: false
      required:
        - expected_generation
        - disconnect_consumer_ids
        - acknowledge_data_loss
      properties:
        expected_generation:
          type: integer
          format: int64
          minimum: 1
          description: >-
            The instance generation the person reviewed; a retirement of any
            other generation is refused.
        disconnect_consumer_ids:
          type: array
          items:
            type: string
            format: uuid
          description: >-
            Exactly the service's consumer binding ids, each once. Omitted or
            null is invalid, never read as an empty list.
        acknowledge_data_loss:
          type: boolean
          description: >-
            Must be true: retiring a service deletes its data, and no export is
            offered.
    ServiceRetirement:
      type: object
      additionalProperties: false
      required:
        - id
        - instance_id
        - plan
        - digest
        - state
        - created_at
        - expires_at
        - execution_id
        - confirmed_at
        - phase
        - settled_at
        - outcome
        - reason
      properties:
        id:
          type: string
          format: uuid
        instance_id:
          type: string
          format: uuid
        plan:
          $ref: '#/components/schemas/ServiceRetirementPlan'
        digest:
          type: string
          pattern: ^sha256:[a-f0-9]{64}$
        state:
          type: string
          enum:
            - pending
            - expired
            - in_progress
            - settled
          description: >-
            pending and expired describe an unconfirmed review's window;
            in_progress and settled a confirmed retirement.
        created_at:
          type: string
          format: date-time
        expires_at:
          type: string
          format: date-time
        execution_id:
          type: string
          format: uuid
          nullable: true
          description: >-
            The confirmation's receipt: the execution carrying out the
            retirement.
        confirmed_at:
          type: string
          format: date-time
          nullable: true
        phase:
          type: string
          enum:
            - retire_stack
            - await_teardown
            - dispose_data
          nullable: true
        settled_at:
          type: string
          format: date-time
          nullable: true
        outcome:
          type: string
          enum:
            - retired
            - removal_failed
            - disposal_unknown
            - refused
            - interrupted
          nullable: true
          description: >-
            Only retired releases the service's name; every other outcome keeps
            it reserved and reason says why.
        reason:
          type: string
          nullable: true
    ServiceRetirementPlan:
      type: object
      additionalProperties: false
      description: >-
        The server-resolved statement of what the retirement removes and keeps.
        The digest covers all of it; nothing in it is supplied by the client.
      required:
        - schema_version
        - instance_id
        - organisation_id
        - actor_id
        - name
        - cluster_id
        - generation
        - namespace
        - stack
        - nothing_deployed
        - owned_draft_id
        - consumers_to_disconnect
        - shared_kept
        - data
        - expires_at
      properties:
        schema_version:
          type: integer
          enum:
            - 1
        instance_id:
          type: string
          format: uuid
        organisation_id:
          type: string
          format: uuid
        actor_id:
          type: string
          format: uuid
        name:
          type: string
        cluster_id:
          type: string
          format: uuid
        generation:
          type: integer
          format: int64
          minimum: 1
        namespace:
          type: string
          nullable: true
          description: >-
            The service's own namespace, deleted once the stack is gone. Null
            when the service owns none (its profile is not a first-party engine)
            or nothing was deployed; then no namespace is deleted.
        stack:
          type: object
          nullable: true
          additionalProperties: false
          description: >-
            The stack Services installed, found by its resource id, with the
            members the retirement removes. Null when nothing was deployed.
          required:
            - resource_id
            - name
            - state
            - members
            - member_digest
          properties:
            resource_id:
              type: string
              format: uuid
            name:
              type: string
            state:
              type: string
              enum:
                - deployed
                - removal_in_progress
                - removed_outside_services
            members:
              type: array
              items:
                type: object
                additionalProperties: false
                required:
                  - id
                  - kind
                  - name
                  - namespace
                properties:
                  id:
                    type: string
                    format: uuid
                  kind:
                    type: string
                    enum:
                      - addon
                      - manifest
                      - application
                      - stack_description
                  name:
                    type: string
                  namespace:
                    type: string
                    nullable: true
                    description: >-
                      Where the member deploys, rendered with the stack's
                      variables; null when that is not knowable from its
                      definition.
            member_digest:
              type: string
              description: >-
                Pins the member set; the retirement lane refuses a stack whose
                members differ.
        nothing_deployed:
          type: boolean
          description: >-
            The installation never submitted a deployment: the retirement
            releases the name and deletes nothing on the cluster beyond the
            installation's own unfinished draft.
        owned_draft_id:
          type: string
          format: uuid
          nullable: true
        consumers_to_disconnect:
          type: array
          items:
            type: object
            additionalProperties: false
            required:
              - id
              - application_id
              - cluster_id
              - namespace
            properties:
              id:
                type: string
                format: uuid
              application_id:
                type: string
                format: uuid
              cluster_id:
                type: string
                format: uuid
              namespace:
                type: string
          description: >-
            The service's consumers. Credentials were never delivered into their
            namespaces, so nothing is removed there.
        shared_kept:
          type: array
          items:
            type: object
            additionalProperties: false
            required:
              - stack_name
              - title
            properties:
              stack_name:
                type: string
              title:
                type: string
          description: >-
            Shared, cluster-wide stacks the service needed (for example the
            CloudNativePG operator). A retirement never removes them.
        data:
          type: object
          additionalProperties: false
          description: >-
            What happens to the service's data, as a statement of what the
            retirement does.
          required:
            - namespace_deleted
            - volumes_deleted
            - secrets_deleted
            - export_offered
            - restore_points
            - statement
          properties:
            namespace_deleted:
              type: boolean
            volumes_deleted:
              type: boolean
            secrets_deleted:
              type: boolean
            export_offered:
              type: boolean
              description: 'Always false: no export runs before deletion.'
            restore_points:
              type: string
              enum:
                - kept_per_vault_retention
            statement:
              type: string
        expires_at:
          type: string
          format: date-time
  securitySchemes:
    BearerAuth:
      bearerFormat: PAT
      scheme: bearer
      type: http

````