API errors
The error codes the Policies API answers with, what causes each and what to do.
Every error is a JSON body. code holds the code, and error a sentence for people, whose wording
can change. module is policies, and correlationId echoes the request's X-Correlation-Id
header when it has one. A code that needs more fields lists them below. The portal shows the
request as rejected; the code says why.
invalid_body
400. The body is not valid JSON, or has a field the API does not know — a misspelt ruleKind, or
a parameter under the wrong name. error ends with the parser's reason. Fix the body; unknown
fields are refused rather than ignored.
validation_failed
400. The policy is well-formed JSON but not a valid policy. violations lists every problem at
once, each with a field and a message:
| Field | Refused when |
|---|---|
name |
It is empty |
ruleKind |
It is not one of the four rules |
parameters.<member> |
The rule's own member is empty, or a member of another rule is set |
parameters.allowedComputePlans, parameters.allowedRegistries |
An entry is blank |
parameters.requiredLabels |
A label key is blank |
clusterId |
The boundary does not span that cluster |
duplicate_name
409. The boundary already has a policy with that name. Choose another name, or change the
existing policy.
policy_not_found
404. The boundary has no policy with the name in the path.
clusters_unavailable
503. The platform could not read which clusters the boundary spans, so the policy was not
stored. Nothing changed; try again.
projection_not_removed
503, on a delete. At least one cluster did not remove the policy; clusters lists their ids.
The policy is not deleted and still applies where it is installed. Try again when the clusters are
reachable.
resource_type_required
400, from GET /boundaries/<boundary-id>/policies/allowed-compute-plans, which answers which
plans the boundary's policies allow. Add ?resourceType=, such as valkeycomputeplans.
invalid_boundary
400. The boundary in the path is not a boundary id.