set_egress_mode

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/set_egress_mode, with a bearer credential and the action's payload as the JSON body.

Contract description

Move one application's outbound-traffic enforcement between observe (an undeclared destination is allowed and recorded) and enforce (it is refused). Super-admin (platform operator) only. The answer names `propagation_seconds` — the proxy's resolve-cache interval, within which every replica holds the new mode; setting observe again is the back-out.

Access and action metadata

{
  "name": "set_egress_mode",
  "resource": "application",
  "tier": "reversible",
  "grant": "super_admin",
  "summary": "Move one application's egress enforcement mode between observe and enforce; the answer names the propagation bound, `propagation_seconds` — the tunnel seat's resolve-cache interval, within which every replica holds the new mode — and the same action to observe is the back-out.",
  "annotations": {
    "readOnlyHint": false,
    "destructiveHint": true,
    "openWorldHint": false
  }
}

MCP catalog entry

{
  "name": "set_egress_mode",
  "tier": "reversible",
  "scenario": "API-L0-12",
  "summary": "Move one application's outbound-traffic enforcement between observe (an undeclared destination is allowed and recorded) and enforce (it is refused). Super-admin (platform operator) only. The answer names `propagation_seconds` — the proxy's resolve-cache interval, within which every replica holds the new mode; setting observe again is the back-out.",
  "owners": [
    "EGW-L0-17",
    "EGW-L0-16",
    "API-L0-12"
  ]
}

request

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["application","mode"]
/properties/application The application id, from `list_applications`.

Type: string
/properties/mode `observe` or `enforce`.

Type: string
Allowed values: ["observe","enforce"]

response

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["contract_version","application","propagation_seconds"]
/properties/contract_version Required value: 1
/properties/reference The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call.

Type: string
Pattern: ^[0-9a-f]{10}$
/properties/application id, label, account, and egress_mode as recorded

Type: object
/properties/propagation_seconds the tunnel seat's resolve-cache interval (EGW-L0-16): the mode is effective at every replica within it

Type: integer
/properties/detail Type: string

Complete payload contract

{
  "request": {
    "type": "object",
    "required": [
      "application",
      "mode"
    ],
    "properties": {
      "application": {
        "type": "string",
        "description": "The application id, from `list_applications`."
      },
      "mode": {
        "type": "string",
        "enum": [
          "observe",
          "enforce"
        ],
        "description": "`observe` or `enforce`."
      }
    }
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "application",
      "propagation_seconds"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "reference": {
        "type": "string",
        "pattern": "^[0-9a-f]{10}$",
        "description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
      },
      "application": {
        "type": "object",
        "description": "id, label, account, and egress_mode as recorded"
      },
      "propagation_seconds": {
        "type": "integer",
        "description": "the tunnel seat's resolve-cache interval (EGW-L0-16): the mode is effective at every replica within it"
      },
      "detail": {
        "type": "string"
      }
    }
  }
}

Shared contracts