> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentsfleet.net/llms.txt
> Use this file to discover all available pages before exploring further.

# Administer a fleet runner

> Platform-admin mutation on a single runner. The body carries exactly one of `action` or `assigned_policy`. `action` moves the admin state: `cordon` to cordoned, `drain` to draining, `revoke` to revoked. Revoked is terminal; a revoked runner cannot transition back. `assigned_policy` re-assigns the runner's policy, and the host picks it up on its next heartbeat. Sending the same policy again changes nothing and records no event.



## OpenAPI

````yaml https://raw.githubusercontent.com/agentsfleet/agentsfleet/main/public/openapi.json patch /v1/fleets/runners/{id}
openapi: 3.1.0
info:
  title: agentsfleet Control Plane API
  version: 1.0.0
  description: API for managing workspaces, fleets, triggers, and runs.
  contact:
    name: agentsfleet
    url: https://agentsfleet.net
servers:
  - url: https://api.agentsfleet.net
    description: Production
security:
  - BearerAuth: []
tags:
  - name: Health
    description: System status and readiness probes
    x-mintlify:
      navigation: Health
  - name: Authentication
    description: Command Line Interface (CLI) sign-in sessions and GitHub sign-in
    x-mintlify:
      navigation: Authentication
  - name: Workspaces
    description: Create and manage workspaces
    x-mintlify:
      navigation: Workspaces
  - name: Tenant
    description: Manage tenant provider settings and models
    x-mintlify:
      navigation: Tenant
  - name: auth-identity-events
    description: >-
      Process signed account events from Clerk. This route is not for customer
      fleets.
    x-mintlify:
      navigation: Auth Identity Events
  - name: Fleets
    description: Create, configure, and run fleets
    x-mintlify:
      navigation: Fleets
  - name: Schedules
    description: Manage and receive scheduled Fleet events
    x-mintlify:
      navigation: Schedules
  - name: Memory
    description: Read and search saved fleet memory
    x-mintlify:
      navigation: Memory
  - name: Secrets
    description: Manage named secrets for fleets in a workspace
    x-mintlify:
      navigation: Secrets
  - name: Admin
    description: Manage shared provider keys and models
    x-mintlify:
      navigation: Admin
  - name: Billing
    description: Read tenant balances and charge records
    x-mintlify:
      navigation: Billing
  - name: Integration Grants
    description: Manage fleet access to third-party services
    x-mintlify:
      navigation: Integration Grants
  - name: Connectors
    description: Connect workspaces to third-party providers
    x-mintlify:
      navigation: Connectors
  - name: Fleet Keys
    description: Manage keys that let external clients call a fleet
    x-mintlify:
      navigation: Fleet Keys
  - name: API Keys
    description: Manage tenant admin API keys
    x-mintlify:
      navigation: API Keys
  - name: Webhooks
    description: Receive signed events and approval decisions
    x-mintlify:
      navigation: Webhooks
  - name: Approvals
    description: List, inspect, and resolve pending approvals
    x-mintlify:
      navigation: Approvals
  - name: Fleet
    description: Enroll and manage runners
    x-mintlify:
      navigation: Fleet
  - name: Fleet Bundles
    description: Manage fleet source bundles in a workspace
    x-mintlify:
      navigation: Fleet Bundles
  - name: Fleet library
    description: Browse and add reusable fleet sources
    x-mintlify:
      navigation: Fleet library
  - name: Model Library
    description: List models available to the tenant
    x-mintlify:
      navigation: Model Library
paths:
  /v1/fleets/runners/{id}:
    patch:
      tags:
        - Fleet
      summary: Administer a fleet runner
      description: >-
        Platform-admin mutation on a single runner. The body carries exactly one
        of `action` or `assigned_policy`. `action` moves the admin state:
        `cordon` to cordoned, `drain` to draining, `revoke` to revoked. Revoked
        is terminal; a revoked runner cannot transition back. `assigned_policy`
        re-assigns the runner's policy, and the host picks it up on its next
        heartbeat. Sending the same policy again changes nothing and records no
        event.
      operationId: patch_fleet_runner
      parameters:
        - name: id
          in: path
          required: true
          description: Runner id (UUIDv7).
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              description: >-
                Exactly one of `action` or `assigned_policy` must be present;
                both or neither is a 400.
              properties:
                action:
                  type: string
                  description: The operator transition to apply.
                  enum:
                    - cordon
                    - drain
                    - revoke
                assigned_policy:
                  $ref: '#/components/schemas/RunnerAssignedPolicy'
      responses:
        '200':
          description: >-
            The runner's admin state, plus the stored assignment on the
            policy-update path.
          content:
            application/json:
              schema:
                type: object
                required:
                  - id
                  - admin_state
                properties:
                  id:
                    type: string
                    format: uuid
                  admin_state:
                    type: string
                    enum:
                      - active
                      - cordoned
                      - draining
                      - drained
                      - revoked
                  assigned_policy:
                    $ref: '#/components/schemas/RunnerAssignedPolicy'
                    x-stability: stable
        default:
          $ref: '#/components/responses/Error'
components:
  schemas:
    RunnerAssignedPolicy:
      type: object
      description: >-
        The policy assigned to one runner. agentsfleet delivers it to the host
        on enrollment and on every heartbeat. The host never declares its own
        policy.
      required:
        - sandbox_tier
        - network_policy
        - registry_allowlist
        - worker_count
      properties:
        sandbox_tier:
          $ref: '#/components/schemas/RunnerSandboxTier'
        network_policy:
          $ref: '#/components/schemas/RunnerNetworkPolicy'
        registry_allowlist:
          type: array
          description: >-
            Operator registry baseline merged into each lease's egress
            allowlist. Empty = the runner substitutes its default registry set.
            Entries are `host[:port]` names; at most 32.
          maxItems: 32
          items:
            type: string
        worker_count:
          type: integer
          description: >-
            Concurrent workers on the host. Clamped server-side into [1, 64];
            the stored (clamped) value is echoed back.
          minimum: 1
          maximum: 64
    RunnerSandboxTier:
      type: string
      description: >-
        Isolation strength the operator assigns to a runner. The host applies it
        and reports what it can deliver. A host that cannot meet the assignment
        is marked degraded and receives no work. Only tiers with real
        enforcement are assignable.
      enum:
        - landlock_full
        - container_nested
        - dev_none
    RunnerNetworkPolicy:
      type: string
      description: >-
        Network access assigned to a runner's sandboxed work. `allow_all` allows
        all outbound traffic. `deny_all_egress` allows none. `allow_list_egress`
        limits outbound traffic to an approved list. That mode is not available
        yet; a runner assigned it is marked degraded and refuses work.
      enum:
        - allow_all
        - deny_all_egress
        - allow_list_egress
    ErrorBody:
      type: object
      description: RFC 7807 problem detail error response (application/problem+json)
      required:
        - docs_uri
        - title
        - detail
        - error_code
        - request_id
      properties:
        docs_uri:
          type: string
          format: uri
          description: Stable link to documentation for this error code
          example: https://docs.agentsfleet.net/api-reference/error-codes#UZ-AGT-009
        title:
          type: string
          description: Short human-readable label, same for every occurrence of this code
          example: Fleet not found
        detail:
          type: string
          description: Instance-specific context describing what went wrong
          example: No fleet with id 'abc123' in this workspace.
        error_code:
          type: string
          description: Machine-readable error code
          example: UZ-AGT-009
        request_id:
          type: string
          description: Correlation ID for this request
        current_state:
          type: string
          description: >-
            Resource state that blocked the requested change. Present only on
            409 responses.
          example: paused
        user_message:
          type: string
          description: >
            Plain message safe to show to a user. Present only when an error
            defines one.


            Use `detail` or `title` when this field is absent.
          example: >-
            We couldn't find that Fleet. It may have been deleted, or the ID
            doesn't match one in this workspace.
        etag:
          type: string
          description: >-
            Resource version returned on 412 responses so the caller can refetch
            and retry.
  responses:
    Error:
      description: RFC 7807 problem detail error response
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Obtain a token via the CLI auth flow (POST /v1/auth/sessions) or GitHub
        OAuth

````