halt_environment
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/halt_environment, with a bearer credential and the action's payload as the JSON body.
Contract description
Halt a deployed environment without deleting it: its hostname answers 503 `environment_halted`, its schedules do not fire, and its version, data, credentials, and declarations stand. Production's compute is stopped, and so is a Pro application's development compute, which holds a warm replica (a container app stopped, or a pod's scaler paused at zero). A Free or Standard development environment scales to zero on its own. The `resume_environment` call ends the halt, as does a deploy to a halted development environment. A halt is refused `deploy_in_flight` while a deploy, promote, or restart of the environment runs. A halt of production while a production deploy is still building its image is admitted and ends that deploy; past its build, the halt is refused until the deploy ends.
A halt of production is an account action: it is admitted under your session or a token minted for the whole account. It is refused `account_credential_required` under a token bounded to one application, so that a leaked application token cannot stop production. A development halt and `resume_environment` are admitted under either token.
Access and action metadata
{
"name": "halt_environment",
"resource": "environment",
"tier": "reversible",
"summary": "Halt a deployed environment without deleting it: its hostname answers 503 `environment_halted`, its schedule rows leave the tick's claim, and its version, data, credentials, and declarations stand; production's compute is stopped, and so is a Pro application's development compute, which holds a warm replica (a container app stopped, or a pod's scaler paused at zero); a Free or Standard development environment scales to zero on its own. A halt on a halted environment answers `unchanged`. A halt of production is an account action: admitted under the account's session or a minted token scoped to the whole account, and refused 403 `account_credential_required` under a minted token bounded to one application, so that a leaked application-bounded token cannot stop production; a development halt and `resume_environment` keep the bounded token's admission. A halt is refused `deploy_in_flight` while a deploy, promote, or restart of the environment runs, save one case. A halt of production while a production deploy is still building its image is admitted and ends that deploy; past its build, the halt is refused until the deploy ends.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": true
}
}
MCP catalog entry
{
"name": "halt_environment",
"tier": "reversible",
"scenario": "CHI-L0-09",
"summary": "Halt a deployed environment without deleting it: its hostname answers 503 `environment_halted`, its schedules do not fire, and its version, data, credentials, and declarations stand. Production's compute is stopped, and so is a Pro application's development compute, which holds a warm replica (a container app stopped, or a pod's scaler paused at zero). A Free or Standard development environment scales to zero on its own. The `resume_environment` call ends the halt, as does a deploy to a halted development environment. A halt is refused `deploy_in_flight` while a deploy, promote, or restart of the environment runs. A halt of production while a production deploy is still building its image is admitted and ends that deploy; past its build, the halt is refused until the deploy ends.\n\nA halt of production is an account action: it is admitted under your session or a token minted for the whole account. It is refused `account_credential_required` under a token bounded to one application, so that a leaked application token cannot stop production. A development halt and `resume_environment` are admitted under either token.",
"owners": [
"PLD-L0-41",
"PLD-L0-47",
"PLD-L0-40"
]
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["application","environment"] |
| / |
The application id, from `list_applications`. Type: string |
| / |
One of the platform's two environments, `development` or `production`. A halt of `production` is an account action: it is admitted under the account's session or a minted token scoped to the whole account. It is refused 403 `account_credential_required` under a minted token bounded to one application, so that a leaked application-bounded token cannot stop production. A halt of `development` is admitted under either token. The halt is a compute act for production and for a development environment whose plan's development replica floor is one (Pro): the container app is stopped, or the pod's scaler is paused at zero replicas. A Free or Standard development environment's compute runs no act, because it scales to zero on its own. A halt is refused `deploy_in_flight` while a deploy, promote, or restart of the environment is in flight, with one exception. A halt of `production` while a production deploy is still building its image is admitted and ends that deploy. Past its build, the halt is refused until the deploy ends. Type: string Pattern: ^(development|production)$ |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | The environment's standing halted state after the call; `unchanged` where a halt found the environment halted or a resume found it running (PLD-L0-41). Type: object Required fields: ["contract_version","application","environment","halted","outcome"] |
| / |
Required value: 1 |
| / |
The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call. Type: string Pattern: ^[0-9a-f]{10}$ |
| / |
Type: string |
| / |
Type: string |
| / |
Null where the environment is running; otherwise the halt's instant and author (PLD-L0-41). Type: ["object","null"] Required fields: ["at","by"] |
| / |
The instant the halt began, in UTC (ISO 8601). Type: string |
| / |
Who halted the environment: `developer` through `halt_environment`, or `platform` through the activity cap of the daily pass (PLD-L0-41). Type: string Allowed values: ["developer","platform"] |
| / |
Type: string Allowed values: ["halted","resumed","unchanged"] |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"application",
"environment"
],
"properties": {
"application": {
"type": "string",
"description": "The application id, from `list_applications`."
},
"environment": {
"type": "string",
"pattern": "^(development|production)$",
"description": "One of the platform's two environments, `development` or `production`. A halt of `production` is an account action: it is admitted under the account's session or a minted token scoped to the whole account. It is refused 403 `account_credential_required` under a minted token bounded to one application, so that a leaked application-bounded token cannot stop production. A halt of `development` is admitted under either token. The halt is a compute act for production and for a development environment whose plan's development replica floor is one (Pro): the container app is stopped, or the pod's scaler is paused at zero replicas. A Free or Standard development environment's compute runs no act, because it scales to zero on its own. A halt is refused `deploy_in_flight` while a deploy, promote, or restart of the environment is in flight, with one exception. A halt of `production` while a production deploy is still building its image is admitted and ends that deploy. Past its build, the halt is refused until the deploy ends."
}
}
},
"response": {
"type": "object",
"required": [
"contract_version",
"application",
"environment",
"halted",
"outcome"
],
"properties": {
"contract_version": {
"const": 1
},
"reference": {
"type": "string",
"pattern": "^[0-9a-f]{10}$",
"description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
},
"application": {
"type": "string"
},
"environment": {
"type": "string"
},
"halted": {
"type": [
"object",
"null"
],
"required": [
"at",
"by"
],
"properties": {
"at": {
"type": "string",
"description": "The instant the halt began, in UTC (ISO 8601)."
},
"by": {
"type": "string",
"enum": [
"developer",
"platform"
],
"description": "Who halted the environment: `developer` through `halt_environment`, or `platform` through the activity cap of the daily pass (PLD-L0-41)."
}
},
"description": "Null where the environment is running; otherwise the halt's instant and author (PLD-L0-41)."
},
"outcome": {
"type": "string",
"enum": [
"halted",
"resumed",
"unchanged"
]
}
},
"description": "The environment's standing halted state after the call; `unchanged` where a halt found the environment halted or a resume found it running (PLD-L0-41)."
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md