SDK reference

SDK reference

Generated from the Rust source the TypeScript and Python packages are built from (crates/ix/sdk-bind). Pick a language in any tab group and every table on the site follows. Names are camelCase in TypeScript and snake_case in Python and Rust.

Objects

Ci

CI runner-pool credentials, reached as client.ci.

Trade a GitHub Actions OIDC token (requested with the ix audience) for a GitHub App installation token scoped to the workflow's own repository.

ci.githubRunnerToken(oidcToken: string): Promise<GithubRunnerToken>

Client

The ix API client.

Connect using an explicit token, or the ambient credential when token is omitted.

new Client(token?: string, baseUrl?: string): Client

The API endpoint this client is talking to.

client.baseUrl(): string

The keys namespace.

client.keys: Keys

The machines namespace.

client.machines: Machines

The snapshots namespace.

client.snapshots: Snapshots

The usage namespace.

client.usage: Usage

The authenticated account.

client.me(): Promise<Me>

The secrets namespace: the ACCOUNT's secret store. One machine's own copies are machines.connect(id).secrets.

client.secrets: Secrets

The ci namespace: credentials for runner pools that run CI on ix machines.

client.ci: Ci

The credits namespace: model spend paid in ix credits.

client.credits: Credits

The groups namespace: private networks between machines.

client.groups: Groups

The previews namespace: disposable copies of a deployment.

client.previews: Previews

The volumes namespace: persistent disks and their snapshots.

client.volumes: Volumes

The observability namespace: traces and logs, correlated by id.

client.observability: Observability

The regions namespace.

client.regions: Regions

Credits

Spend ix credits directly.

Debit amount_microcredits from the account and get a receipt.

credits.burn(amountMicrocredits: number, idempotencyKey: string): Promise<BurnReceipt>

Credit back what a burn did not spend: spent_microcredits of it was used, and the rest returns. Repeating it for a settled burn returns the same outcome.

credits.unburn(burnId: string, spentMicrocredits: number): Promise<CreditBurn>

Groups

The groups namespace: private east-west networks between machines.

Create a group.

groups.create(slug: string): Promise<Group>

Delete a group. Its members lose the overlay; the machines are untouched.

groups.delete(slug: string): Promise<void>

Every group the caller owns.

groups.list(): Promise<Group[]>

Put a machine in a group, resolvable inside it as <dns_name>.ix.internal.

groups.addMember(group: string, machineName: string, dnsName?: string): Promise<AddedMember>

Take a machine out of a group.

groups.removeMember(group: string, machineName: string): Promise<void>

Who is in a group, and at which address.

groups.listMembers(group: string): Promise<GroupMember[]>

Keys

API keys: one capped credential per user or per agent, over the account's single balance.

Mint a key. The returned secret is the only copy that will ever exist in plaintext.

keys.create(name: string, limitUsd?: number, scopes?: string[], expiresAt?: number): Promise<CreatedKey>

Every key on the account, flattened, children tagged with parent_id.

keys.list(includeRevoked?: boolean): Promise<ApiKey[]>

One key by id, whatever its state.

keys.get(id: string): Promise<ApiKey>

Change a key's label, cap, paused state, or scopes.

keys.update(id: string, name?: string, limitUsd?: number, clearLimit?: boolean, disabled?: boolean, scopes?: string[]): Promise<ApiKey>

Permanently revoke a key and every key beneath it.

keys.revoke(id: string): Promise<void>

The key this client is authenticated with: its own cap, spend and headroom. ix keys self on the CLI.

keys.current(): Promise<ApiKey>

A page of one key's burns, newest first: what it spent through Credits::burn and through ix's model gateway, each with what it reserved and what it settled to.

keys.burns(id: string, limit?: number, before?: string): Promise<KeyBurnPage>

Machines

The vms namespace: the account's machines as data.

Every machine the caller owns, in any state.

machines.list(): Promise<MachineInfo[]>

Delete several machines and their disks. Not reversible.

machines.deleteMany(ids: string[]): Promise<DeleteResult[]>

One machine by id, name, or ix_... typed id.

machines.get(machine: string): Promise<MachineInfo>

A handle onto one machine: exec, files, logs, snapshots.

machines.connect(id: string): Machine

The migrations namespace: moving a running machine between nodes.

machines.migrations: Migrations

Create a machine and return a handle onto it, booted.

machines.create(options: CreateMachineOptions): Promise<Machine>

Create a machine, streaming progress as it happens.

machines.createStream(options: CreateMachineOptions): Promise<unibind_runtime::UniStream<MachineProgress>>

The latest resource usage of every machine the caller can see.

machines.metrics(): Promise<MachineUsage[]>

Machine addresses reachable directly from the caller's own network.

machines.localEndpoints(): Promise<LocalEndpoint[]>

Machine

A live machine: commands, files, logs, status, snapshots.

Create a machine and return a handle onto it.

Machine.create(options?: CreateMachineOptions): Promise<Machine>

Adopt a machine that already exists, by name or id.

Machine.attach(machine: string): Promise<Machine>

Every machine the caller owns, in any state.

Machine.list(): Promise<MachineInfo[]>

This machine's id.

machine.id(): string

Whether the create that produced this handle replayed an earlier one instead of booting a new machine.

machine.deduplicated(): boolean

How the create that produced this handle finished waiting for the guest to boot.

machine.readiness(): MachineReadiness

The lifetime this handle created the machine with: persistent or ephemeral (a TTL machine is ephemeral; read Self::ttl).

machine.lifetime: Lifetime | undefined

The deadline this handle created an ephemeral machine with, as a duration string ("1h" for the ephemeral default, "20m" for an explicit one). Absent for a persistent or adopted handle.

machine.ttl: string | undefined

The machine's current record.

machine.info(): Promise<MachineInfo>

Start a stopped machine, and wait for the platform to report it running.

machine.start(): Promise<MachineInfo>

Stop the machine, keeping its disk.

machine.stop(options?: StopOptions): Promise<MachineInfo>

Restart the machine.

machine.restart(options?: RestartOptions): Promise<MachineInfo>

Rename the machine.

machine.rename(name: string): Promise<MachineInfo>

Delete the machine and its disk. Not reversible.

machine.delete(): Promise<void>

Release the handle, deleting the machine only if this handle created it ephemeral.

machine.close(): Promise<void>

Run a command and return its Process at once.

machine.exec(command: string[], options?: ExecOptions): Process

Run a shell script and return its Process at once.

machine.shell(script: string, options?: ExecOptions): Process

Start a command and return its guest pid, without waiting.

machine.spawn(command: string[], cwd?: string): Promise<number>

Read a guest file as text.

machine.readFile(path: string): Promise<string>

Create or truncate a guest file and write text to it.

machine.writeFile(path: string, contents: string): Promise<number>

List a guest directory's direct children.

machine.listDir(path: string): Promise<DirEntry[]>

The most recent log lines.

machine.logs(stream?: LogStream, limit?: number, since?: number): Promise<LogEntry[]>

Follow the machine's logs as they are written, one line per item.

machine.tailLogs(stream?: LogStream): Promise<unibind_runtime::UniStream<String>>

Follow the machine's status.

machine.watch(): Promise<unibind_runtime::UniStream<MachineStatusEvent>>

Whether the guest has finished booting.

machine.isReady(): Promise<boolean>

Wait until the guest finishes booting.

machine.waitReady(timeoutMs?: number): Promise<boolean>

Capture a snapshot of this machine's disk.

machine.snapshot(): Promise<SnapshotRef>

Wait until a captured snapshot is ready to restore.

machine.waitSnapshotReady(snapshotId: string, timeoutMs?: number): Promise<SnapshotWait>

Copy this machine into a new one: snapshot, wait until the snapshot is restorable, restore.

machine.fork(options?: ForkOptions): Promise<Machine>

Open an interactive shell and return the live session.

machine.openShell(command?: string[], cols?: number, rows?: number, term?: string, env?: std::collections::HashMap<String, String>): Promise<ShellSession>

Re-attach to a shell session that is already running.

machine.attachShell(sessionId: number, cols?: number, rows?: number): Promise<ShellSession>

Every shell session on the machine, running or exited-but-unreaped.

machine.listShells(): Promise<ShellInfo[]>

Dial a TCP port inside the machine and return the raw stream.

machine.connectPort(port: number): Promise<ByteStream>

Dial a UDP port inside the machine. The datagram counterpart to Self::connect_port.

machine.connectUdpPort(port: number): Promise<UdpForward>

Attach to the machine's bootstrap console.

machine.openConsole(): Promise<ByteStream>

Start the machine, reporting each phase as it happens.

machine.startStreaming(): Promise<unibind_runtime::UniStream<MachineProgress>>

Follow the machine's logs as raw bytes, exactly as they were written.

machine.tailLogsBytes(stream?: LogStream): Promise<unibind_runtime::UniStream<Vec<u8>>>

Read a guest file as a stream of byte chunks.

machine.readFileStream(path: string, offset?: number, length?: number): Promise<unibind_runtime::UniStream<Vec<u8>>>

This machine's OWN secrets, as distinct from the account store at client.secrets.

machine.secrets: MachineSecrets

Bind a local TCP port that forwards to remote_port in this machine.

machine.forwardPort(remotePort: number, localPort?: number): Promise<PortForward>

Restart this machine's in-guest platform daemons without rebooting it.

machine.reload(guest?: boolean, console?: boolean, agent?: boolean): Promise<ReloadedDaemons>

Send a Magic SysRq key to this machine's guest kernel.

machine.sysrq(letter: string): Promise<void>

This machine's latest resource sample.

machine.metrics(): Promise<MachineMetrics | undefined>

Turn this machine's inbound and outbound internet access on or off.

machine.setInternet(ingress?: boolean, egress?: boolean): Promise<MachineInfo>

Converge this machine's east-west group membership onto exactly groups.

machine.applyGroups(groups: string[]): Promise<GroupChanges>

How long this machine's last start took, stage by stage.

machine.startupInfo(): Promise<StartupInfo | undefined>

Re-apply this machine's networking on the node hosting it.

machine.reconfigureNetwork(): Promise<void>

Read a byte range of a guest file.

machine.readBytes(path: string, offset?: number, length?: number): Promise<number[]>

Read a whole guest file as bytes.

machine.readAllBytes(path: string): Promise<number[]>

Create or truncate a guest file and write bytes to it.

machine.writeAllBytes(path: string, contents: number[], mode?: number): Promise<number>

What the machine's host can see of its live runtime.

machine.runtimeStatus(): Promise<RuntimeStatus>

Migrations

The migrations namespace: moving a running machine between nodes.

Start moving a machine onto another node.

migrations.start(machineId: string, targetNode?: string): Promise<StartedMigration>

The machine's current migration, or nothing when it is not migrating.

migrations.get(machineId: string): Promise<Migration | undefined>

Ask the coordinator to abandon an in-flight migration.

migrations.cancel(machineId: string, migrationId: string): Promise<void>

PortForward

A local TCP port that maps onto a port inside a machine.

The local port now accepting connections.

portForward.localPort(): number

The guest port this forward reaches.

portForward.remotePort(): number

The machine this forward reaches.

portForward.machineId(): string

Stop forwarding and release the local port.

portForward.close(): Promise<void>

Observability

The observability namespace: traces and logs, correlated by id.

Traces matching a correlation id, as summaries.

observability.traces(traceId?: string, requestId?: string, operationId?: string, since?: number, until?: number, limit?: number): Promise<TraceSummary[]>

One trace expanded: a flattened span tree, or the journald fallback. See TraceDetail for which you get and why.

observability.trace(traceId: string): Promise<TraceDetail>

Platform log lines matching a correlation id.

observability.logs(traceId?: string, requestId?: string, operationId?: string, since?: number, until?: number, limit?: number): Promise<PlatformLog[]>

Previews

The previews namespace: disposable copies of a deployment.

Bring up a preview.

previews.create(imageTag?: string, forkVolumes?: boolean): Promise<PreviewDetail>

Every preview, with its service and health counts.

previews.list(): Promise<Preview[]>

One preview, with a row per service.

previews.get(id: string): Promise<PreviewDetail>

Tear a preview down.

previews.stop(id: string): Promise<void>

Make this preview the live deployment.

previews.promote(id: string): Promise<PreviewDetail>

Process

A running command on a machine.

Awaiting a Process calls wait.

Wait for the command to end and return what it produced.

process.wait(): Promise<ExecResult>

The command's stdout as byte chunks, from the start.

process.stdout: unibind_runtime::UniStream<Vec<u8>>

The command's stderr as byte chunks, from the start.

process.stderr: unibind_runtime::UniStream<Vec<u8>>

Both streams merged in arrival order, from the start.

process.output: unibind_runtime::UniStream<OutputChunk>

The merged output as text lines, each stream split on its own.

process.text(): unibind_runtime::UniStream<String>

The command's stdin.

process.stdin: ProcessStdin

Kill the command: close its session so the guest sends SIGTERM, waits a grace window, then SIGKILLs its process group. Resolves once the session is closed. Killing a finished process does nothing.

process.kill(): Promise<void>

ProcessStdin

A running command's stdin.

Write bytes to the command's stdin.

processStdin.write(data: number[]): Promise<void>

Write text to the command's stdin, as UTF-8. Nothing is appended.

processStdin.writeText(text: string): Promise<void>

Close the command's stdin, so a command reading to EOF finishes. Closing twice is fine.

processStdin.close(): Promise<void>

Regions

The regions namespace: where machines can be placed.

Every region this account can place machines in.

regions.list(): Promise<Region[]>

Secrets

The account's secret store: values a machine is built with.

Store a secret, or overwrite one under the same name.

secrets.set(name: string, value: string): Promise<SecretWrite>

Every stored secret's name and timestamps. Never the values.

secrets.list(): Promise<Secret[]>

Delete the ACCOUNT value.

secrets.delete(name: string): Promise<void>

MachineSecrets

One machine's own secrets, reached as machines.connect(id).secrets.

This machine's secrets as metadata: name, injection shape, timestamps. Never the values.

machineSecrets.list(): Promise<MachineSecret[]>

Set one secret on this machine alone.

machineSecrets.set(key: string, value: string): Promise<void>

Remove one secret from this machine.

machineSecrets.delete(key: string): Promise<void>

ShellSession

A live interactive shell on a machine: a real pty, not a command run.

This session's number, for Machine::attach_shell later.

shellSession.id(): number

The shell's exit status, or absent while it is still running.

shellSession.exitCode(): number | undefined

Everything the shell writes, as it writes it.

shellSession.output(): unibind_runtime::UniStream<Vec<u8>>

Send bytes to the shell's input.

shellSession.write(data: number[]): Promise<void>

Send text to the shell's input, as UTF-8.

shellSession.writeText(text: string): Promise<void>

Tell the shell its terminal was resized.

shellSession.resize(cols: number, rows: number): Promise<void>

End the session.

shellSession.close(): Promise<void>

ByteStream

A raw two-way byte stream to a machine.

Bytes arriving from the far end, until it closes.

byteStream.output(): unibind_runtime::UniStream<Vec<u8>>

Send bytes to the far end, flushed before returning.

byteStream.write(data: number[]): Promise<void>

Stop writing and release the read direction.

byteStream.close(): Promise<void>

UdpForward

A UDP tunnel to a port on a machine.

Datagrams arriving from the guest port, one item per packet.

udpForward.datagrams(): unibind_runtime::UniStream<Vec<u8>>

Send one datagram to the guest port.

udpForward.send(payload: number[]): Promise<void>

Close the tunnel.

udpForward.close(): Promise<void>

Snapshots

The snapshots namespace.

Every snapshot captured from one machine, newest first.

snapshots.list(machineId: string): Promise<Snapshot[]>

Restore a snapshot into a NEW machine and return a handle onto it.

snapshots.restore(id: string, name?: string): Promise<Machine>

Restore a snapshot into a new machine, reporting each phase.

snapshots.restoreStreaming(id: string, name?: string): Promise<unibind_runtime::UniStream<MachineProgress>>

Usage

The usage namespace: what the account has spent, and what is left.

The account's balance and lifetime totals.

usage.summary(): Promise<UsageSummary>

The whole billing picture: the money in Self::summary, plus where an unpaid account sits on the grace ladder, its recent purchases, its auto-recharge settings, and the bounds a Self::checkout amount must fall inside.

usage.status(): Promise<BillingStatus>

The individual metered charges against ONE API key, newest first.

usage.events(keyId: string, since?: number, until?: number, resourceType?: string, limit?: number): Promise<UsageEvent[]>

Spend over a window, rolled up by resource type, by individual resource, and by day.

usage.report(since?: number, until?: number, resourceType?: string, limit?: number, bucketSeconds?: number): Promise<UsageReport>

This UTC month's spend: total so far, a projection to month end, compute consumed, and what each machine cost.

usage.monthToDate(now?: number): Promise<MonthSpend>

Open a hosted payment page for buying credit.

usage.checkout(amountMicrocredits: number, savePaymentMethod?: boolean): Promise<Checkout>

Volumes

The volumes namespace: persistent disks and their snapshots.

One volume by id.

volumes.get(id: string): Promise<Volume>

Every volume the caller owns, attached or not.

volumes.list(): Promise<Volume[]>

Every snapshot captured from one volume.

volumes.listSnapshots(id: string): Promise<VolumeSnapshot[]>

Records

BillingLifecycle

Where an account sits on the unpaid-balance ladder.

FieldTypeDescription
phasestringOne of active, compute_grace, data_retention, deleted.
zeroBalanceStartedAtnumber | undefinedWhen the balance first hit zero, if it has.
computeGraceEndsAtnumber | undefinedWhen compute stops running for an unpaid account.
dataRetentionEndsAtnumber | undefinedWhen an unpaid account's data is removed.
deletedAtnumber | undefinedWhen the account was deleted, if it was.

AutoRecharge

Automatic top-up settings.

FieldTypeDescription
enabledbooleanWhether the platform will recharge at all.
thresholdMicrocreditsnumberBalance at or below which a recharge fires.
thresholdUsdnumberThat threshold in US dollars.
amountMicrocreditsnumberHow much each recharge buys.
amountUsdnumberThat amount in US dollars.
paymentMethodIdstring | undefinedSaved payment method selected for automatic recharges.
paymentMethodEligiblebooleanWhether the saved payment method can actually be charged without the customer present. enabled with this false never recharges, which is the state worth noticing before the balance runs out.
lastFailurestring | undefinedWhy the last attempt failed, if one did.

TopUp

One credit purchase.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
amountMicrocreditsnumberWhat was bought.
amountUsdnumberThat amount in US dollars.
statusstringOne of pending, paid, failed, canceled.
savePaymentMethodbooleanWhether the payment method was kept for future charges.
createdAtnumberWhen the purchase was started (Unix epoch milliseconds).
paidAtnumber | undefinedWhen the money landed, if it has.

BillingLimits

Bounds for top-ups and automatic recharge. The server refuses values outside these ranges, so a payment form reads them before submit.

FieldTypeDescription
minimumMicrocreditsnumberSmallest purchase the server accepts.
maximumMicrocreditsnumberLargest purchase the server accepts.
presetsMicrocreditsnumber[]The amounts the platform suggests, in order.
minimumAutoRechargeThresholdMicrocreditsnumberSmallest balance threshold accepted for automatic recharge.
maximumAutoRechargeThresholdMicrocreditsnumberLargest balance threshold accepted for automatic recharge.
minimumAutoRechargeAmountMicrocreditsnumberSmallest automatic recharge amount accepted.
maximumAutoRechargeAmountMicrocreditsnumberLargest automatic recharge amount accepted.

BillingStatus

The account's billing state: money, grace, and how it refills.

FieldTypeDescription
balanceMicrocreditsnumberCredit remaining. Can be negative: the platform lets a balance go under zero rather than cutting a running workload dead.
balanceUsdnumberCredit remaining, in US dollars.
totalAddedMicrocreditsnumberEverything ever added to the account.
totalAddedUsdnumberEverything ever added, in US dollars.
spentMicrocreditsnumberEverything ever spent.
spentUsdnumberEverything ever spent, in US dollars.
lifecycleBillingLifecycleWhere an unpaid account sits on the grace ladder.
topUpsTopUp[]Recent credit purchases.
autoRechargeAutoRechargeAutomatic refill settings.
limitsBillingLimitsBounds a checkout amount must fall inside.

UsageEvent

One metered charge.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
keyIdstringThe API key that incurred the charge.
poolIdstringThe credit pool it was charged against.
resourceTypestringWhat was consumed, e.g. vm_cpu.
quantitynumberHow much of it, in units.
unitstringThe unit quantity is counted in, e.g. vcpu-seconds.
costMicrocreditsnumberWhat it cost.
costUsdnumberThat cost in US dollars.
resourceIdstring | undefinedThe machine, volume or snapshot charged for, when the charge names one.
resourceNamestring | undefinedThat resource's name at the time of the charge.
createdAtnumberWhen the charge was recorded (Unix epoch milliseconds).

AccountActivity

One non-usage change to the account balance, currently a top-up.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
kindstringWhat changed the balance, currently top_up.
amountMicrocreditsnumberAmount of credit involved.
amountUsdnumberThat amount in US dollars.
statusstringOne of pending, paid, failed, canceled.
createdAtnumberWhen the activity was created (Unix epoch milliseconds).
effectiveAtnumber | undefinedWhen it affected the balance, if it has.

ResourceSpend

Spend rolled up by what was consumed.

FieldTypeDescription
resourceTypestringWhat was consumed.
totalQuantitynumberTotal consumption, in that resource's own unit.
costMicrocreditsnumberWhat it cost.
costUsdnumberThat cost in US dollars.

InstanceSpend

Spend rolled up by the individual machine, volume or snapshot behind it.

FieldTypeDescription
resourceTypestringWhat was consumed.
resourceIdstring | undefinedThe resource charged, when the charge names one.
resourceNamestring | undefinedIts name at the time of the charge.
totalQuantitynumberTotal consumption, in that resource's own unit.
costMicrocreditsnumberWhat it cost.
costUsdnumberThat cost in US dollars.
eventCountnumberHow many metered charges rolled into this row.

DailySpend

One calendar day of spend.

FieldTypeDescription
daystringThe day, as the server labels it (YYYY-MM-DD, UTC).
costMicrocreditsnumberWhat that day cost.
costUsdnumberThat cost in US dollars.

UsagePoint

One time bucket of one resource type, for a usage-over-time chart.

FieldTypeDescription
bucketStartnumberStart of the bucket (Unix epoch milliseconds).
resourceTypestringWhat was consumed in it.
totalQuantitynumberTotal consumption over the bucket, in that resource's own unit.
costMicrocreditsnumberWhat the bucket cost.
costUsdnumberThat cost in US dollars.

UsageDimension

One billable dimension of a window, listed even when unused.

FieldTypeDescription
idstringcpu, memory, disk, snapshots, image_storage or egress.
unitstringThe rate card's unit (vcpu_second, gib_second, tib_second, gb).
quantitynumberBilled quantity in the window, in unit.
unitPriceMicrocreditsnumberMicrocredits per unit; not a price while price_is_placeholder.
priceIsPlaceholderbooleanThe price is a TODO-price placeholder: show it as such, never as free.
costMicrocreditsnumberWhat the window cost.
heldBytesnumber | undefinedBytes held right now, for a stored-level dimension.
notestring | undefinedWhat the row does not say on its own.

UsageReport

Spend over a window, rolled up three ways.

FieldTypeDescription
poolIdstringThe credit pool this reports on.
sincenumber | undefinedStart of the window, when one was asked for.
untilnumber | undefinedEnd of the window, when one was asked for.
totalCostMicrocreditsnumberEverything the window cost.
totalCostUsdnumberThat total in US dollars.
byResourceResourceSpend[]Rolled up by what was consumed.
byInstanceInstanceSpend[]Rolled up by which machine, volume or snapshot consumed it.
byDayDailySpend[]Rolled up by day.
seriesUsagePoint[]Bucketed series; empty unless bucket_seconds asked for one.
recentEventsUsageEvent[]Most recent itemized charges within the query window.
accountActivityAccountActivity[]Top-ups and other account-level balance changes within the window.
creditBurnsCreditBurn[]Credits burned within the window, newest first.
dimensionsUsageDimension[]Every billable dimension in order, zero rows included.
unmeteredVmsnumberRunning machines with no disk reading: their disk is not metered.

Checkout

A hosted payment page for buying credit.

FieldTypeDescription
urlstringSend the customer here. The purchase happens on the payment provider's page, not through this API.
sessionIdstringThe provider's session id, for reconciling a webhook.
topUpIdstringThe pending top-up this session will settle.
amountMicrocreditsnumberWhat the session charges.
amountUsdnumberThat amount in US dollars.
statusstringThe session's state as the provider reports it.
savePaymentMethodbooleanWhether the payment method will be kept for future charges.

MachineMonthSpend

What one machine cost this month.

FieldTypeDescription
machineIdstringThe machine's id.
namestring | undefinedIts name at the time of the most recent charge.
costMicrocreditsnumberMonth-to-date cost.
costUsdnumberThat cost in US dollars.

MonthSpend

The current UTC month's spend, with a projection and per-machine cost.

FieldTypeDescription
sincenumberFirst instant of the month (Unix epoch milliseconds, UTC).
untilnumberThe instant this was taken for.
monthEndnumberFirst instant of the next month.
totalCostMicrocreditsnumberEverything spent this month so far.
totalCostUsdnumberThat total in US dollars.
projectedCostMicrocreditsnumber | undefinedThe average pace so far, extended to month end. Absent in the first 24 hours of the month, where it would be noise.
projectedCostUsdnumber | undefinedThe projection in US dollars.
vcpuSecondsnumberCompute consumed, in vCPU-seconds.
byMachineMachineMonthSpend[]Cost per machine, most expensive first. Charges that name no machine (volumes, snapshots, egress) count in the total only.
byDayDailySpend[]Spend per UTC day.
truncatedbooleanTrue when the server's row limit was hit, so by_machine may omit small machines. The total is still exact.

GithubRunnerToken

A short-lived GitHub App installation token for one repository.

FieldTypeDescription
tokenstringThe installation token. Scoped to repository with runner administration permissions and nothing else; GitHub expires it.
expiresAtstringGitHub's own expiry for token (RFC 3339), passed through verbatim: GitHub owns the lifetime.
installationIdnumberThe GitHub App installation the token was minted under. Diagnostic: it names the installation in GitHub's own audit log.
repositorystringowner/name: the only repository token works on.

CreditBurn

One credits.burn, as the platform holds it.

FieldTypeDescription
idstringStable id. Opaque: pass it back to Credits::unburn, never parse it.
amountMicrocreditsnumberDebited from the account, exactly.
amountUsdnumberThat amount in US dollars.
keyIdstring | undefinedThe API key that burned, while its row exists.
createdAtnumberWhen the burn was made.
unburnUnburnOutcome | undefinedHow the burn ended. Absent until it is unburned.
idempotencyKeystringThe idempotency key the burn was made under.

UnburnOutcome

How a burn ended.

FieldTypeDescription
spentMicrocreditsnumberWhat the caller reported spent of the burn.
spentUsdnumberThat spend in US dollars.
returnedMicrocreditsnumberCredited back to the account.
returnedUsdnumberThat credit in US dollars.
unburnedAtnumberWhen it was unburned.

BurnReceipt

What a burn answers with.

FieldTypeDescription
burnIdstringThe burn's id. Opaque: pass it to Credits::unburn.
amountMicrocreditsnumberDebited from the account, exactly.
balanceAfterMicrocreditsnumberThe account balance the burn left; for a deduplicated receipt, the balance the original burn left.
deduplicatedbooleanTrue when the idempotency key named a burn the account had already made, and this is that burn's receipt rather than a new one.

Group

A private network between machines.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
slugstringThe name every other verb here takes.
ulaPrefixstringThe group's own IPv6 /64, in CIDR notation. Members get addresses inside it and nothing outside routes there.

GroupMember

One machine's membership of a group.

FieldTypeDescription
groupIdstringThe group.
machineIdstringThe member machine.
dnsNamestringResolvable inside the group as <dns_name>.ix.internal.
addressstringThe address allocated to this member.

AddedMember

The result of adding a member.

FieldTypeDescription
memberGroupMemberThe committed membership.
attachesOnNextStartbooleanThe machine is running and booted without a NIC for this group, so the overlay attaches on its next start. Until then the membership is real and the interface is not -- which is why this is reported rather than left to be discovered as a peer that will not resolve.

KeyBurn

One burn of a key, and the model gateway call it paid for.

FieldTypeDescription
burnCreditBurnThe burn.
modelCallModelCall | undefinedThe model gateway call this burn paid for. Absent for a burn made through Credits::burn.

ModelCall

The model gateway call behind a burn.

FieldTypeDescription
requestIdstringThe call's request id. Its burn's idempotency key is model-gateway:<request_id>.
modelstringThe model the call named, as the gateway serves it.

KeyBurnPage

One page of Keys::burns, newest first.

FieldTypeDescription
burnsKeyBurn[]The burns on this page.
nextBeforestring | undefinedPass back as before for the next page. Absent once the list is exhausted.

Region

A region a machine can be placed in.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
slugstringThe slug used everywhere a region is named, e.g. us-west-1. This is what create's region argument takes.
displayNamestringHuman-readable name, for a picker.
statusstringWhether the region is accepting work: active accepts placements, provisioning is coming up and not placing yet, draining keeps existing machines running while taking no new ones, and offline is not serving.

ForkOptions

Options for machine.fork().

FieldTypeDescription
namestring | undefinedThe copy's name. The platform generates one when absent.
lifetimeLifetime | undefinedThe copy's lifetime. A fork restores a snapshot and vm.restore has no lease slot, so anything but persistent is refused with InvalidArgument (before any snapshot is taken) rather than creating a persistent copy the caller believes expires.
ttlstring | undefinedThe copy's TTL; refused for the same reason as lifetime.

CreateMachineOptions

Options for creating a machine.

FieldTypeDescription
imagestring | undefinedOCI image reference to boot: registry/repo:tag or registry/repo@sha256:..., such as ix/debian:12 or ghcr.io/owner/repo:1.2. The platform resolves it to a platform manifest digest once, at create; MachineInfo::image_digest reads the answer back.
archArch | undefinedThe architecture to run on. Absent takes the architecture of the cheapest node with capacity, and MachineInfo::arch reads the answer back. An image with no manifest for it raises ImageNotAvailableForArch, listing the architectures it has. Refused when restoring a snapshot, which keeps the architecture it was captured on.
registrySecretstring | undefinedName of a stored secret (see secrets) holding the registry credentials for a private image: basic auth or a registry token. The platform reads it only to resolve and pull, never writes it to the machine, and a secret bound to another registry host raises ImageAuth. Refused when restoring a snapshot.
entrypointstring[] | undefinedReplace the image's ENTRYPOINT, as docker run --entrypoint does. Absent keeps the image's own; an empty list clears it. Refused when restoring a snapshot.
commandstring[] | undefinedReplace the image's CMD, as the trailing arguments of docker run do. Absent keeps the image's own; an empty list clears it. Refused when restoring a snapshot.
snapshotstring | undefinedSnapshot id to restore into a new machine.
lifetimeLifetime | undefinedHow long the machine lives. Absent is persistent: it lives until someone deletes it.
ttlstring | undefinedThe ephemeral deadline: an integer and one unit, s, m, h or d ("30m"), from one minute to seven days. Out of range or malformed is InvalidArgument, never clamped. A ttl alone makes the machine ephemeral; with lifetime: persistent it is refused.
cpuCpu | undefinedPin a host CPU class. Absent lets the scheduler pick any host of the architecture (a baseline machine). A class that contradicts arch is refused. A pinned machine sees its host's real CPU features and restores only on the same class; MachineInfo.cpu reads it back.
namestring | undefinedHuman-readable machine name. The platform generates one when absent.
regionstring | undefinedRegion slug. When absent, IX_REGION applies, then the server's own default region -- the same ladder the CLI's --region flags resolve.
envstd::collections::HashMap<String, String> | undefinedPlaintext environment variables for the image command.
ipv4boolean | undefinedWhether to allocate a public IPv4 address.
secretEnvstd::collections::HashMap<String, String> | undefinedStored secret name to guest environment-variable name.
secretFilesstd::collections::HashMap<String, String> | undefinedStored secret name to guest file path.
groupsstring[] | undefinedEast-west groups joined during creation.
cpuCoresnumber | undefinedHow many vCPUs the machine boots with.
idempotencyKeystring | undefinedName this create, so a retry finds its machine instead of booting a second one.
readyWaitMsnumber | undefinedHow long to wait for the guest's own boot to finish, in milliseconds. Absent means five minutes.

StopOptions

How machine.stop() stops the machine.

FieldTypeDescription
forceboolean | undefinedPower the machine off without waiting for its guest to flush its filesystems. Writes the guest has not flushed are lost; the disk replays its journal on the next start. Absent or false refuses the stop with Conflict, and leaves the machine running, when the guest cannot flush. A guest that can never flush (unreachable, a frozen root filesystem) is stopped only this way, short of deleting it.

RestartOptions

How machine.restart() stops the machine before starting it again.

FieldTypeDescription
forceboolean | undefinedHard-stop the running machine first, as StopOptions::force does. Writes the guest has not flushed are lost.

MachineReadiness

How a create's readiness wait ended, with whichever detail the outcome carries.

FieldTypeDescription
stateReadinessStateWhich of the three outcomes happened. Branch on this.
readyAtstring | undefinedWhen the server observed the guest ready (RFC 3339). Ready only. Informational: it is a timestamp to log, never a signal to act on.
waitedMsnumber | undefinedHow long the wait ran before giving up. NotReady only, and zero exactly when ready_wait_ms was 0 -- which is what tells a wait that was skipped apart from one that was exhausted.
detailstring | undefinedThe last thing the platform observed about the guest, verbatim, for humans. NotReady only, and not always set even there.

MachineMetrics

A machine's resource usage, at a moment.

FieldTypeDescription
machineIdstringThe machine this is about.
cpuPercentnumberCPU used, normalised to the machine's allocated cores: a fully pegged 8-core machine reads 100.0, not 800.0.
memoryBytesnumberGuest memory in use.
memoryLimitBytesnumberGuest memory allocated.
memoryPercentnumberMemory in use as a percentage of the allocation.
ioReadBytesnumberBytes read from disk, cumulative since boot.
ioWriteBytesnumberBytes written to disk, cumulative since boot.
networkRxBytesnumberBytes received, cumulative since boot.
networkTxBytesnumberBytes sent, cumulative since boot.
uptimeSecsnumberHow long the machine has been up.
collectedAtnumberWhen the sample was taken (Unix epoch milliseconds).

MachineUsage

A machine's resource usage as a RATE, from the account-wide sample.

FieldTypeDescription
machineIdstringThe machine this is about.
cpuPercentnumberCPU used, normalised to allocated cores.
memoryBytesnumberGuest memory in use.
memoryLimitBytesnumberGuest memory allocated.
ioReadBytesPerSecnumberDisk read rate.
ioWriteBytesPerSecnumberDisk write rate.
netRxBytesPerSecnumberInbound network rate.
netTxBytesPerSecnumberOutbound network rate.
collectedAtnumberWhen the sample was taken (Unix epoch milliseconds).

LocalEndpoint

A machine address reachable directly from the caller's own network.

FieldTypeDescription
machineIdstringThe machine this address belongs to.
ipv6stringThe machine's IPv6 address, which is also its identity.
ipv4string | undefinedIts IPv4 VIP, when one is allocated.

ReloadedDaemons

Which in-guest daemons a reload restarted, and their new PIDs.

FieldTypeDescription
ixVmGuestPidnumber | undefinedNew PID of the guest-side machine supervisor.
ixConsolePidnumber | undefinedNew PID of the console bridge behind shell and the log streams.
ixAgentPidnumber | undefinedNew PID of the in-guest agent behind exec, files, and forwards.

StartupInfo

How long a machine's last start took, stage by stage.

FieldTypeDescription
modestringHow the machine came up: full_boot, golden_restore, or fork_restore. A full boot is the slow path; the two restores resume a captured image.
totalMsnumberWall time from the start request to a usable guest.
rootfsPrepareMsnumber | undefinedMaterializing the root filesystem.
bootMsnumber | undefinedThe guest kernel booting.
goldenTemplateMsnumber | undefinedWaiting on the golden template this machine restored from.
createTapMsnumber | undefinedCreating the host-side network tap.
spawnVmmMsnumber | undefinedSpawning the VMM process.
vsockWaitMsnumber | undefinedWaiting for the guest's vsock channel to answer.
guestReadyMsnumber | undefinedWaiting for the guest to report itself ready.

GroupChanges

What an apply_groups reconcile actually changed.

FieldTypeDescription
addedstring[]Slugs this call joined the machine to, sorted.
removedstring[]Slugs this call removed the machine from, sorted.

DeleteResult

The outcome of deleting one machine in delete_many.

FieldTypeDescription
idstringThe machine the delete was for.
deletedbooleanTrue once the platform accepted the delete.
errorCodestring | undefinedThe IxError variant name (NotFound, Conflict, ...) when the delete failed.
errorMessagestring | undefinedThe failure's message.

StartedMigration

A migration that has just been started.

FieldTypeDescription
idstringIdentifies this ATTEMPT, not the machine. This is what cancel takes.
phasestringThe phase the coordinator recorded when the row was created.

Migration

A machine migration in flight, or the last one attempted.

FieldTypeDescription
idstringIdentifies this attempt, not the machine. This is what cancel takes.
machineIdstringThe machine being moved.
sourceNodeIdstringThe node it is moving off.
targetNodeIdstringThe node it is moving onto.
phasestringWhere it has got to. completed, failed and cancelled are the terminal ones; everything else means still in flight.
blackoutUsnumber | undefinedHow long the guest's vCPUs ran nowhere at all, in microseconds: from the source pausing them to the target resuming them, measured across the two hosts. This is the number that says whether the migration was live in practice, and the only one a caller should show a user as downtime.
pauseUsnumber | undefinedHow long the SOURCE held the guest paused inside its capture call, in microseconds.
bytesTransferrednumber | undefinedBytes moved to the target so far.
failureReasonstring | undefinedWhy it failed, when it did.
createdAtnumberWhen the migration was started (Unix epoch milliseconds).

Attribute

One key/value on a span, an event, or a log line.

FieldTypeDescription
keystringThe attribute name.
valuestringIts value, rendered as text.

TraceSummary

One trace, as a search result.

FieldTypeDescription
traceIdstringThe trace id, which is what trace(..) expands.
rootSpanNamestring | undefinedThe name of the outermost span, when there is one.
serviceNamesstring[]Every service the trace touched.
startedAtnumberWhen the trace started (Unix epoch milliseconds).
endedAtnumberWhen it finished.
durationMsnumberHow long it took.
requestIdstring | undefinedThe API request it belongs to, if any.
operationIdstring | undefinedThe long-running operation it belongs to, if any.
spanCountnumberHow many spans it contains.

TraceSpan

One span in a trace.

FieldTypeDescription
spanIdstringThis span's id.
parentSpanIdstring | undefinedIts parent's id. Absent on a root span.
depthnumberHow deep it sits: 0 for a root, 1 for its children, and so on.
namestringThe span's name.
kindstringIts kind, e.g. server, client, internal.
serviceNamestringThe service that emitted it.
startedAtnumberWhen it started (Unix epoch milliseconds).
durationNsnumberHow long it took, in nanoseconds. Nanoseconds, not milliseconds: a span shorter than a millisecond is the common case in a trace and rounding it to zero would make the waterfall unreadable.
statusCodestringIts status, e.g. ok or error.
statusMessagestring | undefinedWhy it failed, when it did.
requestIdstring | undefinedThe API request it belongs to, if any.
operationIdstring | undefinedThe long-running operation it belongs to, if any.
attributesAttribute[]Attributes set on the span itself.

TraceEvent

One journald record correlated to a trace, in the flat fallback.

FieldTypeDescription
timestampnumberWhen it was written (Unix epoch milliseconds).
unitstringThe systemd unit that wrote it.
spanNamestring | undefinedThe span it was written inside, when it was.
severitystring | undefinedSeverity, derived from the journal priority.
messagestringThe line itself.
fieldsAttribute[]Remaining structured fields.

TraceWarning

A node whose journal could not be fully read, so a partial trace is visibly partial rather than silently short.

FieldTypeDescription
hostnamestringThe node.
detailstringWhat went wrong: a timeout, an RPC failure, truncation.

TraceDetail

One trace, expanded.

FieldTypeDescription
traceIdstringThe trace this describes.
sourcestringclickhouse or journald; see above.
spansTraceSpan[]The span tree, flattened pre-order. Empty on the journald path.
eventsTraceEvent[]Flat journald records. Empty on the ClickHouse path.
warningsTraceWarning[]Nodes the journald fan-out could not fully read.

PlatformLog

One platform log line.

FieldTypeDescription
timestampnumberWhen it was emitted (Unix epoch milliseconds).
traceIdstring | undefinedThe trace it belongs to, if any.
spanIdstring | undefinedThe span it was emitted inside, if any.
severitystring | undefinedSeverity as the producer set it.
serviceNamestringThe service that emitted it.
bodystringThe line itself.
eventNamestring | undefinedThe structured event name, when the line is one.
requestIdstring | undefinedThe API request it belongs to, if any.
operationIdstring | undefinedThe long-running operation it belongs to, if any.
attributesAttribute[]Remaining structured fields.

Preview

A disposable deployment, as the list reports it.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
imageTagstringThe image tag it was brought up from.
statusstringThe preview's own status.
serviceCountnumberHow many services it runs.
healthyCountnumberHow many of them are healthy. Equal to service_count when the preview is fully up.
createdAtnumberWhen it was created (Unix epoch milliseconds).

PreviewService

One service inside a preview.

FieldTypeDescription
namestringThe service's name.
statusstringIts status.

PreviewDetail

A preview with a row per service: the diagnosis view, where the list's counts are the dashboard view.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
imageTagstringThe image tag it was brought up from.
statusstringThe preview's own status.
createdAtnumberWhen it was created (Unix epoch milliseconds).
servicesPreviewService[]Every service, and where each one got to.

ExecOptions

Options for Machine::exec and Machine::shell.

FieldTypeDescription
cwdstring | undefinedGuest directory to run in. Absent is the guest's default.
stdinboolean | undefinedOpen the command's stdin, so process.stdin can write to it and close it. Without it the command reads /dev/null.
checkboolean | undefinedRaise IxError::CommandFailed from the await when the command exits non-zero, instead of returning the exit code as a result.
maxBuffernumber | undefinedHow many bytes of each stream the awaited result keeps; 16 MiB when absent. Past it the result sets truncated. The live streams are never capped.

OutputChunk

One chunk of a command's merged output.

FieldTypeDescription
streamOutputStreamWhich stream wrote it.
atMsnumberMilliseconds since the process started, measured by the client as the chunk arrived. Arrival order, not a guest clock: when one guest write carries both streams, stdout comes first.
datanumber[]The bytes, exactly as written. A chunk boundary can fall inside a multi-byte character, so decode across chunks, or read text.

MachineProgress

One step of a long-running machine operation, or its result.

FieldTypeDescription
kindstringEvent name, e.g. PullingImage, StepStarted, or Finished / Failed on the terminal frame.
messagestringHuman-readable message. Empty when the phase carries none.
finishedbooleanWhether this is the terminal frame. Prefer this to comparing kind: it is a boolean the compiler can check, where a string sentinel is one typo away from a loop that never ends.
machineMachineInfo | undefinedSet on the terminal frame only: the finished machine.
errorstring | undefinedSet on the terminal frame only, and only when the operation failed. Exactly one of machine and error is set there.
deduplicatedboolean | undefinedSet on a successful CREATE's terminal frame: whether the create replayed an earlier one carrying the same idempotencyKey instead of booting a new machine. Absent on start and restore frames, which have no key to replay.
readinessMachineReadiness | undefinedSet on a successful CREATE's terminal frame: how its wait for the guest to boot ended. Absent on start and restore frames.
stepIdnumber | undefinedThe instrumented step this belongs to, for the Step* phases. Correlates a StepStarted with its later StepProgress and StepDone, which matters once steps interleave.
machineIdstring | undefinedThe machine this phase is about, when it names one. Also set on the terminal frame, where it is machine.id.
nodestring | undefinedAllocatingVm: physical node the machine was placed on.
regionstring | undefinedAllocatingVm: public region slug, e.g. us-west-1.
donenumber | undefinedStepProgress: items completed so far.
totalnumber | undefinedStepStarted / StepProgress: total items, so a determinate bar can render done out of total.
elapsedMsnumber | undefinedWall time spent in the phase or substep.
fileCountnumber | undefinedRootfsConverted: files in the converted image.
blockCountnumber | undefinedRootfsConverted: blocks in the converted image.
totalBytesnumber | undefinedRootfsConverted: total bytes.
fromCacheboolean | undefinedRootfsConverted: whether the conversion cache was reused.
itemCountnumber | undefinedManifest file or chunk-reference count, by stage.
cachedboolean | undefinedIndexingRootfsManifest: whether a cached manifest was found.
cacheReasonstring | undefinedIndexingRootfsManifest: why the cache did or did not hit.
newChunksnumber | undefinedRegisteredRootfsChunks: legacy per-chunk-ref count.
committedAtnumber | undefinedServerVersion: when the serving build was committed (Unix epoch seconds).

ShellInfo

One shell session running on a machine.

FieldTypeDescription
idnumberSession number, as Machine::attach_shell takes it.
commandstring[]The argv the session was started with.
attachedbooleanWhether a client is attached right now.
exitedbooleanWhether the process has exited. An exited session still lists until it is reaped, so its output can be read one last time.

Scope

One permission grant on a key.

FieldTypeDescription
resourcestringResource family, e.g. vm.
actionsstring[]Actions permitted on it. ["*"] is every action.
portsnumber[] | undefinedGuest ports a vm:port_forward grant reaches. Absent means every port, which is what every other grant carries.

ApiKey

An API key, as the platform holds it.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
namestringCaller-chosen label. Not unique, not an identifier.
keyPrefixstring | undefinedLeading, non-secret slice of the key, for display.
scopesScope[]The permissions this key carries.
limitMicrocreditsnumber | undefinedSpend cap, or absent for uncapped.
limitUsdnumber | undefinedSpend cap in US dollars, derived from the integer above.
consumedMicrocreditsnumberSpent against the cap so far. Lags real usage by seconds: metering is asynchronous, so a cap is an optimistic circuit breaker.
consumedUsdnumberSpend so far in US dollars, derived from the integer above.
remainingMicrocreditsnumber | undefinedCap minus consumption, or absent when uncapped.
remainingUsdnumber | undefinedHeadroom in US dollars, derived from the integer above.
statestringOne of active, disabled, revoked. disabled is reversible and keeps the secret; revoked is permanent and cascades.
createdAtnumberWhen the key was minted (Unix epoch milliseconds).
expiresAtnumber | undefinedWhen the key stops authenticating on its own, if ever.
lastUsedAtnumber | undefinedLast successful authentication, if any.
parentIdstring | undefinedThe key this one was minted under, if it is a child.

MachineInfo

A machine, as the platform holds it.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
namestringCaller-chosen name, unique within the account.
imageReferencestringThe OCI reference the machine was created from, as the caller gave it (ix/debian:12). Empty for a machine created before images were resolved to digests.
imageDigeststringThe sha256:<hex> digest of the per-architecture manifest the machine runs. Tags are for humans and this is what ran: re-creating from the same tag later can give a different digest. A restart, restore or fork keeps it. Empty for a machine created before images were resolved to digests.
archArch | undefinedThe architecture the machine runs on, as recorded at create. Absent for a machine created before the platform recorded it; never an assumed value.
cpuCpu | undefinedThe host CPU class the machine is pinned to. Absent for a baseline machine (any host of its architecture), which is every machine created without cpu.
statusMachineStatusWhat the machine's lifecycle is doing.
ipv6stringThe machine's IPv6 address, which is also its identity on the network.
ipv4string | undefinedIPv4 address, when one is allocated.
memoryMibnumberGuest RAM.
cpuCoresnumberGuest vCPUs.
regionstring | undefinedRegion slug, when the machine is placed in one.
internetIngressbooleanWhether the machine accepts inbound internet traffic.
internetEgressbooleanWhether the machine may send outbound internet traffic.
failureReasonstring | undefinedWhy the machine failed, when it did. Absent on a healthy machine.
createdAtnumberWhen the machine row was created (Unix epoch milliseconds).
startedAtnumber | undefinedWhen the machine last started, if it ever has.
stoppedAtnumber | undefinedWhen the machine last stopped, if it ever has.

ExecResult

What a finished command produced: what awaiting a Process returns.

FieldTypeDescription
exitCodenumberThe process's exit status. Zero is success.
stdoutstringThe first maxBuffer bytes the process wrote to stdout, decoded as UTF-8 with invalid sequences replaced. Read process.stdout for the exact bytes.
stderrstringThe first maxBuffer bytes the process wrote to stderr, decoded the same way.
truncatedbooleanWhether either stream wrote more than maxBuffer (16 MiB each by default) and the rest was dropped from this result. The live streams are never capped.

LogEntry

One line of machine output.

FieldTypeDescription
timestampnumberWhen the line was emitted (Unix epoch milliseconds).
streamLogStreamWhich capture it came from.
messagestringThe line itself.

DirEntry

One entry in a guest directory.

FieldTypeDescription
namestringEntry name, without its parent path.
pathstringFull path inside the guest.
isDirbooleanWhether the entry is a directory.
sizenumberSize in bytes. Zero for directories.
modenumberPOSIX mode bits.
modifiedAtnumberLast modification (Unix epoch milliseconds).

MachineStatusEvent

A machine's status, at a moment.

FieldTypeDescription
machineIdstringThe machine this is about.
statusMachineStatusWhat the machine's lifecycle is doing.
timestampnumberWhen the server observed it (Unix epoch milliseconds).

Snapshot

A point-in-time capture of a machine.

FieldTypeDescription
idstringStable id. This is what restore takes -- NOT the machine's id.
machineIdstringThe machine this was captured from.
parentIdstring | undefinedThe snapshot this one was captured on top of, if any.
statusSnapshotStatusHow far along the capture is. Only a SnapshotStatus::Ready snapshot can be restored.
memoryMibnumberGuest RAM captured with it.
createdAtnumberWhen the capture started (Unix epoch milliseconds).

UsageSummary

The account's balance and lifetime totals.

FieldTypeDescription
balanceMicrocreditsnumberCredit remaining. Can be negative: the platform lets a balance go under zero rather than cutting a running workload dead.
balanceUsdnumberCredit remaining, in US dollars.
totalAddedMicrocreditsnumberEverything ever added to the account.
totalAddedUsdnumberEverything ever added, in US dollars.
spentMicrocreditsnumberEverything ever spent.
spentUsdnumberEverything ever spent, in US dollars.

CreatedKey

A freshly minted key and its secret.

FieldTypeDescription
keyApiKeyThe key, exactly as list would later report it.
secretstringThe raw secret to authenticate with. Store it now.

Me

The authenticated account.

FieldTypeDescription
idstringStable user id.
usernamestringLogin handle.
emailstring | undefinedContact address, if the account has one.

SnapshotRef

A captured snapshot and the machine it was captured from.

FieldTypeDescription
snapshotIdstringThe snapshot's id. This is what snapshots.restore takes.
machineMachineInfoThe machine as it stood when the capture was taken.

RuntimeStatus

What the platform can see of a machine's live runtime, from its host.

FieldTypeDescription
presentbooleanWhether the platform is tracking this machine's runtime at all. When false every field below is absent and Self::absence_reason says why -- a stopped machine has no runtime, and that is not a fault.
absenceReasonstring | undefinedWhy there is no runtime to report: not_tracked_by_node_agent or not_tracked_by_vmm. Absent when Self::present.
statestring | undefinedThe VMM's state machine position: running, paused, pause_requested, capture_requested, captured, shutdown_requested, shutdown, failed, running_and_capturing, or unknown.
memoryMibnumber | undefinedGuest RAM the VMM currently has plugged in. Moves under virtio-mem, so it is not necessarily the machine's configured size.
guestRpcTransportReadyboolean | undefinedWhether the guest RPC transport has come up. This is the channel exec and the filesystem verbs ride, so false explains why they fail on a machine that is otherwise running.
virtioMemTransportReadyboolean | undefinedWhether the virtio-mem transport has come up.
healthstring | undefinedThe worker's overall verdict: healthy, degraded, or failed. Absent when the VMM reported no health block.
issuesstring[]Every subsystem fault currently present, as subsystem.slot: diagnostic, e.g. control.guest_rpc_transport: ... or vcpu.3: .... Empty on a healthy machine.

Secret

One stored account secret. Metadata only, never the value.

FieldTypeDescription
namestringThe name the value is stored under, and the name a machine reads it by.
createdAtnumberWhen it was first stored (Unix epoch milliseconds).
updatedAtnumberWhen it was last overwritten.

SecretRotation

How far a rotation propagated.

FieldTypeDescription
machinesUpdatednumbermachines whose stored copy was refreshed.
filesRefreshednumberFile-injected secrets rewritten inside running guests.
pendingNextBootnumberCopies whose new value applies at the machine's next start: env-injected secrets, and anything on a stopped machine.
failedMachinesstring[]machines the push could not reach.
failedRegionsstring[]Regions whose machine enumeration failed, so machines there were not visited at all.

SecretWrite

The result of storing an account secret.

FieldTypeDescription
secretSecretThe stored secret's metadata.
rotationSecretRotation | undefinedPresent only when the write OVERWROTE an existing value. Absent on a first write, because there was nothing to propagate.

MachineSecret

One secret materialized into a single machine. Metadata only.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
namestringThe name the guest reads it by.
injectAsstringHow the guest receives it: env or file.
createdAtnumberWhen it was materialized (Unix epoch milliseconds).
updatedAtnumberWhen it was last refreshed.

Volume

A persistent disk.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
namestringCaller-chosen name.
machineIdstring | undefinedThe machine it is attached to, if any.
sizeBytesnumberSize on disk, in bytes.
createdAtnumberWhen it was created (Unix epoch milliseconds).
updatedAtnumberWhen it last changed.

VolumeSnapshot

A point-in-time capture of a volume.

FieldTypeDescription
idstringStable id. Opaque: pass it back, never parse it.
volumeIdstringThe volume this was captured from.
namestringCaller-chosen name.
createdAtnumberWhen it was captured (Unix epoch milliseconds).
esc
  • Loading