Skip to main content
PUT
Update Sidecar

Path Parameters

nameOrID
string
required

Name or UUID of the sidecar

Body

application/json

The request body resource

configuration
object
required

The daemon configuration this sidecar serves. Replaces the stored document entirely.

Response

OK

applied_revision
string
Example:

"8f14e45fceea167a5a36dedd4bea2543"

bound_rules
object[]

BoundRules names the rules the control plane distributes to this sidecar, and the listener each one lands on.

They are NOT inside Configuration and never will be: a bound rule is folded into the SERVED document on every handshake and nothing is stored, so one row update reaches a fleet. That is also why this field has to exist — a page reading Configuration alone shows a listener enforcing nothing while the sidecar enforces the rule.

bound_rules_unavailable
boolean

BoundRulesUnavailable is true when the bindings could not be read. BoundRules is then empty because it is unknown, not because nothing is bound, and a page must not read it as "no rules".

config_state
string

ConfigState is what the sidecar runs, read from the fields above and the clock: applied, applying (served under a heartbeat ago, not reported yet), not_applied (served longer ago and never reported, the shape of a sidecar that exits at boot on it), refused (by the sidecar), not_served (the control plane refused to serve this build, LastError says why), restart, or unknown (a build too old to report). Empty while nothing was served, before the first handshake, and for a sidecar running its own file; a refusal shows even then.

Example:

"applied"

configuration
object

The stored daemon configuration.

created_at
string

Creation timestamp

created_by
string

Subject of the admin who created it

deprecations
string[]

Deprecations lists the deprecated spellings the stored configuration still uses, phrased for an operator. The sidecar folds them on load, where nobody reads the warning.

detached_rules
object

DetachedRules names the rules an owner switch removed, on the PATCH that switched. Deleted rules came from this sidecar's file; unbound rules stay for their other targets.

id
string<uuid>
read-only

Unique identifier

last_error
string

LastError is the reason the sidecar gave with a refused or restart outcome. Empty otherwise.

Example:

"the control plane sent a config this build refuses: parse config: json: unknown field \"future_key\""

last_outcome
string

LastOutcome is what the sidecar did with the last configuration it handled: applied, unchanged, restart, refused or retry.

It is the field that separates a sidecar enforcing the current rules from one that refused them and kept the old ones. A refusal, or a document needing a restart, leaves the sidecar handshaking on time with stale rules, and nothing else tells the two apart.

Empty for a sidecar that has handled nothing yet, or one too old to report. Empty must read as unknown, never as converged.

Example:

"applied"

last_seen_at
string

Last time the sidecar handshook. Empty until it does.

name
string

Human-readable name

Example:

"payments-sidecar"

org_id
string<uuid>
read-only

Organization ID

served_revision
string

ServedRevision names the configuration last answered to this sidecar, and AppliedRevision the one it says it is running. Equal means the sidecar is enforcing what the control plane holds.

Both are opaque: the control plane issues them and compares them to itself. Nothing parses them.

Example:

"8f14e45fceea167a5a36dedd4bea2543"

version
string

Version reported at the last handshake. Empty until the sidecar calls.

Example:

"1.0.0"