import requests
url = "https://platform.ankra.app/api/v1/clusters/upcloud/{cluster_id}/bastion/allowed-ips"
payload = { "bastion_allowed_ips": ["<string>"] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({bastion_allowed_ips: ['<string>']})
};
fetch('https://platform.ankra.app/api/v1/clusters/upcloud/{cluster_id}/bastion/allowed-ips', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request PUT \
--url https://platform.ankra.app/api/v1/clusters/upcloud/{cluster_id}/bastion/allowed-ips \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"bastion_allowed_ips": [
"<string>"
]
}
'{
"node_id": "<string>",
"kind": "<string>",
"name": "<string>",
"bastion_allowed_ips": [
"<string>"
],
"operation_id": "<string>"
}{
"detail": "Cluster not found"
}{
"detail": "Cluster not found"
}{
"detail": "Cluster not found"
}{
"detail": "Cluster not found"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}{
"detail": "Cluster not found"
}Update bastion SSH allowlist
Bearer PAT authentication; RBAC permission clusters.write. Replaces the cluster’s bastion SSH source allowlist and dispatches the bastion update that applies it: the bastion’s SSH port then accepts only the listed IPv4 sources, the platform’s own egress addresses and private network sources, and drops everything else. An empty list clears the allowlist. Clusters that never set one keep SSH open from anywhere.
import requests
url = "https://platform.ankra.app/api/v1/clusters/upcloud/{cluster_id}/bastion/allowed-ips"
payload = { "bastion_allowed_ips": ["<string>"] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({bastion_allowed_ips: ['<string>']})
};
fetch('https://platform.ankra.app/api/v1/clusters/upcloud/{cluster_id}/bastion/allowed-ips', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request PUT \
--url https://platform.ankra.app/api/v1/clusters/upcloud/{cluster_id}/bastion/allowed-ips \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"bastion_allowed_ips": [
"<string>"
]
}
'{
"node_id": "<string>",
"kind": "<string>",
"name": "<string>",
"bastion_allowed_ips": [
"<string>"
],
"operation_id": "<string>"
}{
"detail": "Cluster not found"
}{
"detail": "Cluster not found"
}{
"detail": "Cluster not found"
}{
"detail": "Cluster not found"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}{
"detail": "Cluster not found"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
PAT organisation override.
Path Parameters
Body
The complete new allowlist: IPv4 addresses or CIDRs allowed to reach the bastion's SSH port, besides the platform's own egress addresses, which are always allowed. An empty list clears the allowlist and makes the bastion reachable from anywhere again. IPv6 and 0.0.0.0/0 entries are refused.
64Response
Successful response
The bastion (OVH: gateway) resource id.
The bastion resource kind.
The bastion name.
The stored allowlist, normalised (a bare address becomes /32, host bits are masked, duplicates dropped). Empty means the bastion accepts SSH from anywhere.
The operation that applies the list to the bastion. Null when nothing was scheduled: the list already matched, the cluster is stopped (it applies on start), or an active operation already covers the bastion.