Appearance
DNSMON
9 endpoints at a glance
| Method | Path | Summary |
|---|---|---|
POST | /atlas/dnsmon/refresh/ | Refresh Dnsmon Anchors |
GET | /dnsmon/anchors/ | List DNSMON anchors |
GET | /dnsmon/anchors/history/ | DNSMON membership changes |
POST | /dnsmon/refresh/ | Refresh the DNSMON anchor set |
GET | /dnsmon/replacement-candidates/ | DNSMON anchors with active health issues |
GET | /dnsmon/replacement-candidates/{anchor_id}/suggestions/ | Ranked replacement suggestions for a failing anchor |
GET | /dnsmon/replacements/ | List tracked replacement decisions |
POST | /dnsmon/replacements/ | Propose a replacement |
PATCH | /dnsmon/replacements/{decision_id}/ | Transition a replacement decision |
List DNSMON anchors
GET
/dnsmon/anchors/
Current DNSMON anchors (hostname-sorted).
active only by default; ?include_removed=true also returns
soft-removed rows (kept for forensics). updated is the most
recent per-row refresh stamp so the UI can show data freshness.
Parameters
Query Parameters
include_removed
Type
boolean
Default
falseResponses
Successful Response
application/json
JSON "additionalProperties": "string"
{
}
DNSMON membership changes
DNSMON anchors with active health issues
GET
/dnsmon/replacement-candidates/
Active DNSMON anchors that currently carry active health
issues — the anchors that should be replaced — each with its open
issue set (key / opened-at / context) for the reasons display.
Staff-gated to match the /anchors-health/ posture (issue
context is operational detail). Read-only — choosing the
replacement anchor is a separate task.
Parameters
Header Parameters
authorization
x-api-key
Responses
Successful Response
application/json
JSON "additionalProperties": "string"
{
}
Ranked replacement suggestions for a failing anchor
GET
/dnsmon/replacement-candidates/{anchor_id}/suggestions/
Healthy substitute anchors for one failing DNSMON anchor,
ranked same-country → same-RIR → same-continent → global then by
distance. ?stability=30d|90d sets the quality bar. Staff-gated.
400 on an unknown anchor / bad stability.
Parameters
Header Parameters
authorization
x-api-key
Path Parameters
anchor_id*
Type
Requiredinteger
Query Parameters
stability
Type
string
Default
"30d"limit
Type
integer
Default
0Responses
Successful Response
application/json
JSON "additionalProperties": "string"
{
}
List tracked replacement decisions
Propose a replacement
POST
/dnsmon/replacements/
Record a proposed replacement. Admin-gated. 409 when an
open decision already exists for the candidate; 422 when the
candidate isn't a current failing anchor or the replacement isn't
eligible.
Parameters
Header Parameters
authorization
x-api-key
Request Body
application/json
JSON "candidate_anchor_id": 0, "replacement_anchor_id": 0, "reason": "string"
{
}
Responses
Successful Response
application/json
JSON "additionalProperties": "string"
{
}
Transition a replacement decision
PATCH
/dnsmon/replacements/{decision_id}/
Advance a decision (approved / done / dismissed),
appending an audit event. Admin-gated. 404 unknown id; 400 bad
id / illegal transition.
Parameters
Header Parameters
authorization
x-api-key
Path Parameters
decision_id*
Type
Requiredstring
Request Body
application/json
JSON "status": "string", "reason": "string"
{
}
Responses
Successful Response
application/json
JSON "additionalProperties": "string"
{
}
Refresh the DNSMON anchor set
POST
/dnsmon/refresh/
Admin-panel trigger: pull the upstream list and reconcile
db.anchors_dnsmon (sanity-guarded; soft-remove + add/removed
history). Single HTTP call + small bulk-write. Wrapped in
:func:run_and_record so it lands in db.task_history next to
the scheduled run (trigger="manual").
Parameters
Header Parameters
authorization
x-api-key
Responses
Successful Response
application/json
JSON "additionalProperties": "string"
{
}
Refresh Dnsmon Anchors
POST
/atlas/dnsmon/refresh/
Pull the DNSMON anchor set and reconcile db.anchors_dnsmon.
Single upstream HTTP call + a small bulk-write — sub-second.
Bootstraps a fresh deploy (the next daily tick can be ~24h away)
and is the manual recovery handle if the scheduled job fails.
Sanity-guarded so a bad upstream response can't wipe the set.
Routed through :func:run_and_record so it lands in
db.task_history next to the scheduled run (trigger="manual").
Authorizations
APIKeyQuery
Type
API Key (query: api-key)
or
APIKeyHeader
Type
API Key (header: x-api-key)
Responses
Successful Response
application/json
JSON
[
]