コンテンツにスキップ

A downloadable archive of this deployment's logs and status.

GET
/api/v1/system/support-bundle
curl --request GET \
--url https://example.com/api/v1/system/support-bundle \
--header 'Authorization: Bearer <token>'

Written for a deployment behind an air gap: every entry is text, MANIFEST.json lists what is carried and what is deliberately not, and a redaction scan over the assembled bytes aborts the export rather than shipping a secret.

since_hours
integer format: int32

Hours of log history to carry. Clamped to [1, 168]; the appender’s own retention is usually the tighter bound.

node_id
string format: uuid

The node this bundle is about. When set, the archive gains a node/ section describing exactly that node: what it is and which poller holds it, its stored interface rows, the metrics it is configured to collect, which of those are actually arriving, and its alerts.

Omitting it is not an error — the rest of the bundle is unchanged, and the manifest names this parameter so a reader who needed the section learns it exists.

A gzipped tar of JSON and text files: build provenance, every system-health section, the environment allow-list, applied migrations, table sizes, active alerts, the audit tail, the Prometheus scrape, and rotated log files — core’s, any co-located poller’s, and any remote-site poller’s that answered a request on the bus within the collection deadline. With node_id, also a node/ section describing that one node — its inventory row and owning poller, its stored interface rows, the metrics it is configured to collect, which of those are arriving, and its alerts. Carries no secrets — see MANIFEST.json’s omitted and redaction sections

Media typeapplication/gzip

No valid bearer token

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Role lacks any of ManageSystem, ManageCredentials or ViewAudit

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

The redaction scan matched, so nothing was released. The rule and the file are named in the log, never the value

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Inventory storage is unavailable (skeleton mode)

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}