Skip to main content
PUT
Update bastion SSH allowlist

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

x-ankra-organisation-id
string

PAT organisation override.

Path Parameters

cluster_id
string<uuid>
required

Body

application/json
bastion_allowed_ips
string[]
required

The complete new allowlist: IPv4 addresses or CIDRs allowed to reach the bastion's SSH port, besides the platform's own egress addresses, which are always allowed. An empty list clears the allowlist and makes the bastion reachable from anywhere again. IPv6 and 0.0.0.0/0 entries are refused.

Maximum array length: 64

Response

Successful response

node_id
string
required

The bastion (OVH: gateway) resource id.

kind
string
required

The bastion resource kind.

name
string
required

The bastion name.

bastion_allowed_ips
string[]
required

The stored allowlist, normalised (a bare address becomes /32, host bits are masked, duplicates dropped). Empty means the bastion accepts SSH from anywhere.

operation_id
string | null
required

The operation that applies the list to the bastion. Null when nothing was scheduled: the list already matched, the cluster is stopped (it applies on start), or an active operation already covers the bastion.