set_egress_mode
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/set_egress_mode, with a bearer credential and the action's payload as the JSON body.
Contract description
Move one application's outbound-traffic enforcement between observe (an undeclared destination is allowed and recorded) and enforce (it is refused). Super-admin (platform operator) only. The answer names `propagation_seconds` — the proxy's resolve-cache interval, within which every replica holds the new mode; setting observe again is the back-out.
Access and action metadata
{
"name": "set_egress_mode",
"resource": "application",
"tier": "reversible",
"grant": "super_admin",
"summary": "Move one application's egress enforcement mode between observe and enforce; the answer names the propagation bound, `propagation_seconds` — the tunnel seat's resolve-cache interval, within which every replica holds the new mode — and the same action to observe is the back-out.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": false
}
}
MCP catalog entry
{
"name": "set_egress_mode",
"tier": "reversible",
"scenario": "API-L0-12",
"summary": "Move one application's outbound-traffic enforcement between observe (an undeclared destination is allowed and recorded) and enforce (it is refused). Super-admin (platform operator) only. The answer names `propagation_seconds` — the proxy's resolve-cache interval, within which every replica holds the new mode; setting observe again is the back-out.",
"owners": [
"EGW-L0-17",
"EGW-L0-16",
"API-L0-12"
]
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["application","mode"] |
| / |
The application id, from `list_applications`. Type: string |
| / |
`observe` or `enforce`. Type: string Allowed values: ["observe","enforce"] |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","application","propagation_seconds"] |
| / |
Required value: 1 |
| / |
The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call. Type: string Pattern: ^[0-9a-f]{10}$ |
| / |
id, label, account, and egress_mode as recorded Type: object |
| / |
the tunnel seat's resolve-cache interval (EGW-L0-16): the mode is effective at every replica within it Type: integer |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"application",
"mode"
],
"properties": {
"application": {
"type": "string",
"description": "The application id, from `list_applications`."
},
"mode": {
"type": "string",
"enum": [
"observe",
"enforce"
],
"description": "`observe` or `enforce`."
}
}
},
"response": {
"type": "object",
"required": [
"contract_version",
"application",
"propagation_seconds"
],
"properties": {
"contract_version": {
"const": 1
},
"reference": {
"type": "string",
"pattern": "^[0-9a-f]{10}$",
"description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
},
"application": {
"type": "object",
"description": "id, label, account, and egress_mode as recorded"
},
"propagation_seconds": {
"type": "integer",
"description": "the tunnel seat's resolve-cache interval (EGW-L0-16): the mode is effective at every replica within it"
},
"detail": {
"type": "string"
}
}
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md