> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Preview managed service eligibility

> Answers which catalogue package versions and modes one application environment - the namespace an application is, or is about to be, deployed to on a cluster - could set up right now, and for each that it cannot, the reason and what to do: a cluster with no data policy, a cluster that does not deploy through the Ankra native engine, a playground short of capacity, a mode that is not available (Ankra-hosted), a missing permission, and the rest a prepare refuses with. It runs the checks a prepare runs, through the same code, in a transaction it rolls back: no review is recorded, no name reserved and no review quota spent; the name is the one check it cannot make, since the name is chosen at setup. The service is previewed on the environment's own cluster with the package's default settings. An environment that is not bound yet is checked the way setup would bind it, which needs the application deployed in that namespace. Capacity the platform cannot establish reads unknown, never fits. It is a preview, not a reservation: it takes no lock, so a review quota, capacity or policy that changes before the setup is prepared can still refuse it, and the prepare answers authoritatively. Requires the applications rollout, applications.read and clusters.read on the cluster to ask, and profiles.read to read the catalogue; a member who may read but not deploy gets every mode blocked with permission_required. package_version_id checks one version; otherwise limit (default 10, at most 25) and after page the catalogue in its own order.



## OpenAPI

````yaml https://platform.ankra.app/openapi.json get /api/v1/org/service-admission/eligibility
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
tags:
  - name: Organisation IAM
    description: >-
      Custom organisation roles and scoped role assignments for member and
      service-account identities.
  - name: Clusters
    description: Create, inspect and manage clusters, and the stacks deployed on them.
  - name: Managed Clusters
    description: Provider-managed control planes, driven through one common surface.
  - name: Imported Clusters
    description: Clusters that already existed and were connected to Ankra.
  - name: Cluster Access
    description: Kubeconfigs, service-account tokens and per-cluster access grants.
  - name: Kubernetes
    description: Read and act on the Kubernetes objects inside a cluster.
  - name: AWS Clusters
    description: >-
      Provision and manage self-managed k3s / kubeadm clusters on AWS EC2 in
      your own VPC.
  - name: Ankra Cloud Clusters
    description: >-
      Provision and manage self-managed kubeadm / k3s clusters on Ankra Cloud
      servers: a private network, a NAT router and a bastion per cluster.
  - name: DigitalOcean Clusters
    description: Provision and manage DigitalOcean Kubernetes clusters.
  - name: Hetzner Clusters
    description: Provision and manage Hetzner Kubernetes clusters.
  - name: OVH Clusters
    description: Provision and manage OVH Kubernetes clusters.
  - name: Scaleway Clusters
    description: Provision and manage Scaleway Kapsule clusters.
  - name: UpCloud Clusters
    description: Provision and manage UpCloud Kubernetes clusters.
  - name: Applications
    description: Deploy, configure and observe applications across the fleet.
  - name: Pipelines
    description: >-
      Pipeline definitions, the approval of the authority they declare, and the
      caches pipelines keep between runs.
  - name: Deploy Targets
    description: >-
      Environments, the hosts registered to receive deployments, and the
      releases deployed to them.
  - name: Backups
    description: >-
      Backup vaults, restore points, protection posture and captures for stacks
      and application deployments; a completed capture is not a verified
      restore.
  - name: Stack Profiles
    description: Reusable stack definitions, their versions and sharing.
  - name: Services
    description: >-
      Versioned service packages and explicit sharing. Runtime admission is
      separate from publication.
  - name: Charts
    description: Browse the chart catalogue behind stacks and addons.
  - name: Helm
    description: Helm registries, credentials and the charts they expose.
  - name: Executions
    description: Long-running platform executions and their jobs.
  - name: Operations
    description: Cancel in-flight cluster operations and their jobs.
  - name: Chat
    description: Conversational sessions, plans and confirmable actions.
  - name: AI Management
    description: >-
      Customer agent lifecycle, authenticated identity and organisation
      automation controls.
  - name: AI Agent Runs
    description: Autonomous agent runs and their outcomes.
  - name: AI Tickets
    description: The AI ticket board, its sync connections and settings.
  - name: AI Playbooks
    description: Reusable playbooks the AI lanes execute.
  - name: AI Conditions
    description: Conditions that gate AI autonomy.
  - name: AI Remediation
    description: >-
      The organisation's auto-remediation policy: what the AI lanes may fix by
      themselves, and who approves the rest.
  - name: AI Engineering Handoffs
    description: Work the AI lanes escalate to a human engineer.
  - name: AI Environment
    description: The environment and base stacks AI demos deploy into.
  - name: Security
    description: Findings, advisories, SBOMs, compliance and posture.
  - name: Cost
    description: Cluster and fleet cost, rate cards and cost settings.
  - name: Decisions
    description: >-
      The decision ledger behind the Security and Cost queues: proposals a
      surface computed, the approve and set-aside decisions people took on them,
      and the receipts of running them.
  - name: Usage
    description: >-
      What your organisation used of Ankra - vCPU-hours, playgrounds, managed
      services, hosted logs and metrics, and AI - per meter and period, with how
      completely it was measured and whether a published rate applies.
  - name: Billing
    description: Subscription and spend caps.
  - name: Organisation
    description: Members, invitations, audit logs and organisation settings.
  - name: Account
    description: >-
      Your own account: the contact email Ankra mails when it differs from your
      sign-in address.
  - name: Account Tokens
    description: Personal access tokens for the API and CLI.
  - name: Credentials
    description: The shared credential store.
  - name: AWS Credentials
    description: >-
      AWS credentials: access keys or CloudFormation-onboarded STS roles for
      cost, EKS and self-managed provisioning.
  - name: Ankra Cloud Credentials
    description: >-
      Ankra Cloud API tokens, shared by the self-managed and managed Ankra Cloud
      lanes.
  - name: Azure Credentials
    description: Azure credentials and SSH keys.
  - name: DigitalOcean Credentials
    description: DigitalOcean credentials and SSH keys.
  - name: Hetzner Credentials
    description: Hetzner credentials and SSH keys.
  - name: OVH Credentials
    description: OVH credentials and SSH keys.
  - name: Scaleway Credentials
    description: Scaleway credentials.
  - name: UpCloud Credentials
    description: UpCloud credentials and SSH keys.
  - name: Data Source Credentials
    description: Credentials for metrics and log sources.
  - name: DNS Credentials
    description: Credentials for DNS providers.
  - name: Object Storage Buckets
    description: >-
      Buckets Ankra creates and manages on an organisation's own provider
      credentials.
  - name: DNS
    description: DNS zones and records, including custom organisation zones.
  - name: Cloudflare
    description: Cloudflare domains and the credentials behind them.
  - name: Avura
    description: >-
      The linked Avura organization, the domains it shares with Ankra Platform,
      and their DNS records.
  - name: Variables
    description: Organisation- and cluster-scoped variables.
  - name: SOPS
    description: Encrypt and decrypt values with the organisation SOPS config.
  - name: Alerts
    description: Alert integrations and ingest credentials.
  - name: Notifications
    description: Notification routes and their delivery targets.
  - name: Support
    description: Support tickets.
  - name: AI Settings
    description: Organisation AI provider, model catalog and per-function model settings
paths:
  /api/v1/org/service-admission/eligibility:
    get:
      tags:
        - Services
      summary: Preview managed service eligibility
      description: >-
        Answers which catalogue package versions and modes one application
        environment - the namespace an application is, or is about to be,
        deployed to on a cluster - could set up right now, and for each that it
        cannot, the reason and what to do: a cluster with no data policy, a
        cluster that does not deploy through the Ankra native engine, a
        playground short of capacity, a mode that is not available
        (Ankra-hosted), a missing permission, and the rest a prepare refuses
        with. It runs the checks a prepare runs, through the same code, in a
        transaction it rolls back: no review is recorded, no name reserved and
        no review quota spent; the name is the one check it cannot make, since
        the name is chosen at setup. The service is previewed on the
        environment's own cluster with the package's default settings. An
        environment that is not bound yet is checked the way setup would bind
        it, which needs the application deployed in that namespace. Capacity the
        platform cannot establish reads unknown, never fits. It is a preview,
        not a reservation: it takes no lock, so a review quota, capacity or
        policy that changes before the setup is prepared can still refuse it,
        and the prepare answers authoritatively. Requires the applications
        rollout, applications.read and clusters.read on the cluster to ask, and
        profiles.read to read the catalogue; a member who may read but not
        deploy gets every mode blocked with permission_required.
        package_version_id checks one version; otherwise limit (default 10, at
        most 25) and after page the catalogue in its own order.
      operationId: previewServiceEligibilityToken
      parameters:
        - name: application_id
          in: query
          required: true
          description: The application whose environment is previewed.
          schema:
            type: string
            format: uuid
        - name: cluster_id
          in: query
          required: true
          description: >-
            The cluster the environment deploys to; the service is previewed
            there.
          schema:
            type: string
            format: uuid
        - name: namespace
          in: query
          required: true
          description: The namespace the application deploys to on that cluster.
          schema:
            type: string
            pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
            maxLength: 63
        - name: package_version_id
          in: query
          required: false
          description: Check this package version only.
          schema:
            type: string
            format: uuid
        - name: limit
          in: query
          schema:
            type: integer
            minimum: 1
            maximum: 25
            default: 10
        - name: after
          in: query
          required: false
          description: The catalogue cursor from the previous page.
          schema:
            type: string
            format: uuid
      responses:
        '200':
          description: >-
            The environment, and the verdict for every mode of each package
            version checked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceEligibilityPage'
        '400':
          description: Bearer token not provided or invalid authorization header
        '401':
          description: Authentication required
        '403':
          description: >-
            Insufficient permission: applications.read, clusters.read on the
            cluster, or profiles.read
        '404':
          description: >-
            The application, the cluster or the package version is not
            accessible, or the rollout is disabled
        '409':
          description: >-
            The package version asked for pins a withdrawn or changed profile
            version, or the preview runtime is unavailable
        '422':
          description: >-
            Invalid or ambiguous query: a missing or malformed application_id,
            cluster_id or namespace, an unknown or repeated key, a limit outside
            1-25, or after together with package_version_id
        '500':
          description: Internal error
        '503':
          description: Rollout availability could not be verified
      security:
        - BearerAuth: []
components:
  schemas:
    ServiceEligibilityPage:
      type: object
      additionalProperties: false
      required:
        - environment
        - items
        - next_cursor
      properties:
        environment:
          $ref: '#/components/schemas/ServiceEligibilityEnvironment'
        items:
          type: array
          maxItems: 25
          items:
            $ref: '#/components/schemas/ServicePackageEligibility'
        next_cursor:
          type: string
          format: uuid
          nullable: true
          description: >-
            The catalogue's continuation; pass it as after for the next page.
            Null when the catalogue has no more versions.
    ServiceEligibilityEnvironment:
      type: object
      additionalProperties: false
      required:
        - application_id
        - application_name
        - cluster_id
        - cluster_name
        - namespace
        - consumer_id
      properties:
        application_id:
          type: string
          format: uuid
        application_name:
          type: string
          nullable: true
          description: For display; null when the application's record carries no name.
        cluster_id:
          type: string
          format: uuid
        cluster_name:
          type: string
          description: For display.
        namespace:
          type: string
        consumer_id:
          type: string
          format: uuid
          nullable: true
          description: >-
            The environment's stored binding; null when it is not bound yet,
            which setup does before it prepares a review.
    ServicePackageEligibility:
      type: object
      additionalProperties: false
      required:
        - package
        - reason
        - modes
      properties:
        package:
          $ref: '#/components/schemas/ServicePackageSummary'
        reason:
          anyOf:
            - $ref: '#/components/schemas/ServiceEligibilityReason'
            - type: 'null'
          description: >-
            Set when the package's contract cannot be used at all - a pinned
            profile version was withdrawn or changed - and modes is then empty.
        modes:
          type: array
          items:
            $ref: '#/components/schemas/ServiceModeEligibility'
          description: >-
            Every mode the package declares, in the order hosted, customer,
            existing.
    ServicePackageSummary:
      type: object
      additionalProperties: false
      properties:
        id:
          type: string
          format: uuid
        publisher_id:
          type: string
          format: uuid
        name:
          type: string
        version:
          type: string
        capability:
          type: string
        digest:
          type: string
          pattern: ^sha256:[a-f0-9]{64}$
        first_party:
          type: boolean
          description: >-
            True for a version the Ankra platform publishes itself, readable by
            every organisation the rollout admits without a share.
        created_at:
          type: string
          format: date-time
      required:
        - id
        - publisher_id
        - name
        - version
        - capability
        - digest
        - first_party
        - created_at
    ServiceEligibilityReason:
      type: object
      additionalProperties: false
      required:
        - code
        - message
        - fix
      description: >-
        Why a mode is blocked or unknown. code is the stable vocabulary a client
        keys on; message and fix are words a person reads.
      properties:
        code:
          type: string
          enum:
            - hosted_unavailable
            - not_installable
            - permission_required
            - data_policy_required
            - deployment_unavailable
            - native_engine_required
            - insufficient_capacity
            - credential_inputs_required
            - review_quota
            - package_deprecated
            - package_changed
            - configuration_changed
            - no_longer_available
            - placement_refused
            - environment_not_connected
            - capacity_unknown
        message:
          type: string
          description: What stands in the way.
        fix:
          type: string
          description: What to do next.
    ServiceModeEligibility:
      type: object
      additionalProperties: false
      required:
        - mode
        - state
        - reason
        - capacity
        - secret_inputs
      properties:
        mode:
          type: string
          enum:
            - hosted
            - customer
            - existing
        state:
          type: string
          enum:
            - available
            - blocked
            - unknown
          description: >-
            available: a prepare would accept it now, and the cluster's capacity
            fits it or is not one the platform checks. blocked: a prepare would
            refuse it now; reason says why and what to do. unknown: the answer
            could not be established - the platform cannot tell whether the
            service fits the cluster's capacity (a prepare would accept it with
            the same warning), or the environment must be connected before an
            existing service can be checked against it.
        reason:
          anyOf:
            - $ref: '#/components/schemas/ServiceEligibilityReason'
            - type: 'null'
          description: Null exactly when state is available.
        capacity:
          anyOf:
            - $ref: '#/components/schemas/ServiceCapacityAssessment'
            - type: 'null'
          description: >-
            The service cluster's capacity as the preview assessed it; null when
            the checks stopped before capacity was assessed.
        secret_inputs:
          type: array
          items:
            type: string
          description: The credential inputs a setup in this mode must reference by grant.
    ServiceCapacityAssessment:
      type: object
      additionalProperties: false
      required:
        - state
        - reason
        - plan_id
        - quota
        - committed
        - transient
        - required
      description: >-
        Whether the service cluster can admit the service, assessed exactly as a
        prepare assesses it. Only playgrounds are checked, because the platform
        sets their quota.
      properties:
        state:
          type: string
          enum:
            - fits
            - short
            - unknown
            - unchecked
          description: >-
            fits: the service fits the playground's quota alongside what is
            committed now. short: it does not, and a prepare is refused.
            unknown: the cluster is a playground but the estimate could not be
            made; a prepare proceeds with this as its warning. unchecked: the
            platform sets no quota for this cluster, or the package is not a
            first-party engine; nothing is claimed about its room.
        reason:
          type: string
          description: What decided the state, in sentences.
        plan_id:
          type: string
          description: The playground plan whose quota was checked; empty when none was.
        quota:
          anyOf:
            - $ref: '#/components/schemas/ServiceCapacityResources'
            - type: 'null'
          description: The plan's quota. Null when the decision did not reach it.
        committed:
          anyOf:
            - $ref: '#/components/schemas/ServiceCapacityResources'
            - type: 'null'
          description: >-
            What the tenant's pods and the virtual control plane commit now, Job
            pods excluded. Null when the decision did not reach it.
        transient:
          anyOf:
            - $ref: '#/components/schemas/ServiceCapacityResources'
            - type: 'null'
          description: >-
            What running Job pods hold until they finish. Null when the decision
            did not reach it.
        required:
          anyOf:
            - $ref: '#/components/schemas/ServiceCapacityResources'
            - type: 'null'
          description: >-
            What the service, and its shared operator when the installer adds
            one, needs. Null when the decision did not reach it.
    ServiceCapacityResources:
      type: object
      additionalProperties: false
      required:
        - limits_cpu_millicores
        - limits_memory_mib
        - requests_cpu_millicores
        - requests_memory_mib
      properties:
        limits_cpu_millicores:
          type: integer
          format: int64
        limits_memory_mib:
          type: integer
          format: int64
        requests_cpu_millicores:
          type: integer
          format: int64
        requests_memory_mib:
          type: integer
          format: int64
      description: >-
        A footprint on the four CPU and memory lines a playground's quota
        carries.
  securitySchemes:
    BearerAuth:
      bearerFormat: PAT
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.