Skip to main content

GET /api/ready

Readiness -- is this Gateway's client build admitted by the key server?

Answers 200 when the key server admits this Gateway's release, and 503 when it does not. Every key-server connection the Gateway opens attests the signed release it runs right after it authenticates; a refusal takes the whole process out of readiness, and while it is out every route but this one and GET /api/health answers 503 BUILD_NOT_ADMITTED.

It asks the key server nothing. It reports the admission state the Gateway's own connections establish, held in memory, so polling it costs the key server nothing. The Gateway re-attempts admission on a timer (TE_ATTEST_RETRY_SECONDS, default 30) and turns ready without a restart once the key server admits it -- route a load balancer on this, restart on GET /api/health.

Open for the reason GET /api/health is: the caller is a load balancer or an operator and holds no credential. When ready it discloses nothing but that; when not ready it names the cause, which describes this Gateway's own release and installation.

Authentication​

No session required. This operation is reachable without an Authorization header. See Authenticating.

Request​

No request body.

Responses​

200​

This Gateway's release is admitted; it is serving.

FieldTypeRequiredDescription
status"ready" (constant)yes

Example

{
"status": "ready"
}

503​

BUILD_NOT_ADMITTED (scope: process, retryable: true, Retry-After) -- the key server does not admit this Gateway's release, and detail names why: the key server's own refusal, a release manifest that is not configured while the key server enforces a code-signing level, or an installed file that no longer matches the signed manifest (the file is named).

Error handling​

Every failure answers JSON carrying at least code and detail. Match on code — detail is written for a human debugging the call and its wording is not part of the contract. See the error model.

StatusMeaning
503BUILD_NOT_ADMITTED (scope: process, retryable: true, Retry-After) -- the key server does not admit this Gateway's release, and detail names why: the key server's own refusal, a release manifest that is not configured while the key server enforces a code-signing level, or an installed file that no longer matches the signed manifest (the file is named).