From 10a04fcccbd02ab734e3d229dce3b314e0002e48 Mon Sep 17 00:00:00 2001 From: Brad Ison Date: Tue, 29 Sep 2026 13:36:45 +0200 Subject: [PATCH] [management] Add a disabled state to the managed Agent Network proxy API (#7744) A managed Agent Network gateway can be turned off by the platform. The derived state had no value for that, so a disabled deployment reported whatever the operator last saw, usually provisioning. Add `disabled` to the AgentNetworkManagedProxy state enum and say in the POST and GET descriptions that a disabled deployment answers with it and that provisioning again does not turn it back on. --- shared/management/http/api/openapi.yml | 8 ++++---- shared/management/http/api/types.gen.go | 7 +++++-- 2 files changed, 9 insertions(+), 6 deletions(-) diff --git a/shared/management/http/api/openapi.yml b/shared/management/http/api/openapi.yml index c19df4fcf..3dd9f41f1 100644 --- a/shared/management/http/api/openapi.yml +++ b/shared/management/http/api/openapi.yml @@ -6453,8 +6453,8 @@ components: example: "d1m3kebd9pcs0c1pnu7g" state: type: string - description: Derived deployment state. `provisioning` until the gateway is rolled out and connected, `ready` while the gateway actively serves the endpoint, `failed` when the rollout reported a failure. - enum: [ "provisioning", "ready", "failed" ] + description: Derived deployment state. `provisioning` until the gateway is rolled out and connected, `ready` while the gateway actively serves the endpoint, `failed` when the rollout reported a failure, `disabled` while the gateway is turned off and the endpoint is not served. + enum: [ "provisioning", "ready", "failed", "disabled" ] example: "ready" endpoint: type: string @@ -13575,7 +13575,7 @@ paths: /api/integrations/agent-network/managed-proxy: post: summary: Provision a managed Agent Network gateway - description: Starts provisioning of a NetBird-managed Agent Network gateway for the account, allocating its endpoint under the managed zone on the first call. Idempotent — answers 202 when this call started (or, after a failure, restarted) provisioning and 200 when a deployment already exists, reporting current state either way. Returns 409 when the account already has an Agent Network endpoint that managed provisioning does not own, and 503 when endpoint allocation is temporarily exhausted. + description: Starts provisioning of a NetBird-managed Agent Network gateway for the account, allocating its endpoint under the managed zone on the first call. Idempotent — answers 202 when this call started (or, after a failure, restarted) provisioning and 200 when a deployment already exists, reporting current state either way. A disabled deployment answers 200 with state `disabled` and stays disabled. Returns 409 when the account already has an Agent Network endpoint that managed provisioning does not own, and 503 when endpoint allocation is temporarily exhausted. tags: [ Agent Network ] security: - BearerAuth: [ ] @@ -13613,7 +13613,7 @@ paths: $ref: '#/components/schemas/ErrorResponse' get: summary: Retrieve managed Agent Network gateway status - description: Reports the account's managed gateway deployment and its derived state. Returns 404 when the account has no managed deployment. + description: Reports the account's managed gateway deployment and its derived state, including `disabled` for a deployment that is turned off. Returns 404 when the account has no managed deployment. tags: [ Agent Network ] security: - BearerAuth: [ ] diff --git a/shared/management/http/api/types.gen.go b/shared/management/http/api/types.gen.go index b5a7a80ac..9a90a72d3 100644 --- a/shared/management/http/api/types.gen.go +++ b/shared/management/http/api/types.gen.go @@ -79,6 +79,7 @@ func (e AgentNetworkConsumptionDimensionKind) Valid() bool { // Defines values for AgentNetworkManagedProxyState. const ( + AgentNetworkManagedProxyStateDisabled AgentNetworkManagedProxyState = "disabled" AgentNetworkManagedProxyStateFailed AgentNetworkManagedProxyState = "failed" AgentNetworkManagedProxyStateProvisioning AgentNetworkManagedProxyState = "provisioning" AgentNetworkManagedProxyStateReady AgentNetworkManagedProxyState = "ready" @@ -87,6 +88,8 @@ const ( // Valid indicates whether the value is a known member of the AgentNetworkManagedProxyState enum. func (e AgentNetworkManagedProxyState) Valid() bool { switch e { + case AgentNetworkManagedProxyStateDisabled: + return true case AgentNetworkManagedProxyStateFailed: return true case AgentNetworkManagedProxyStateProvisioning: @@ -2259,11 +2262,11 @@ type AgentNetworkManagedProxy struct { // Region Region of the cluster hosting the deployment. Region *string `json:"region,omitempty"` - // State Derived deployment state. `provisioning` until the gateway is rolled out and connected, `ready` while the gateway actively serves the endpoint, `failed` when the rollout reported a failure. + // State Derived deployment state. `provisioning` until the gateway is rolled out and connected, `ready` while the gateway actively serves the endpoint, `failed` when the rollout reported a failure, `disabled` while the gateway is turned off and the endpoint is not served. State AgentNetworkManagedProxyState `json:"state"` } -// AgentNetworkManagedProxyState Derived deployment state. `provisioning` until the gateway is rolled out and connected, `ready` while the gateway actively serves the endpoint, `failed` when the rollout reported a failure. +// AgentNetworkManagedProxyState Derived deployment state. `provisioning` until the gateway is rolled out and connected, `ready` while the gateway actively serves the endpoint, `failed` when the rollout reported a failure, `disabled` while the gateway is turned off and the endpoint is not served. type AgentNetworkManagedProxyState string // AgentNetworkManagedProxyConflict Conflict body returned when the account already has an Agent Network endpoint that managed provisioning does not own, naming that endpoint.