> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Apply Application Env Secrets

> Apply the application's stored environment secrets to what is already running: re-seal them into the Secrets the manifests read on every deployment and roll the workloads that read them. An application whose last key has been cleared applies too, and the apply then removes the sealed Secret from the deployment's stack and rolls the workloads off those values - without it, every reconcile put the deleted values back. The values only reach a running workload at deploy time otherwise, so this is the explicit one-click close of that gap - it is never triggered implicitly by setting a value. It takes no body (the values it applies are the ones already stored) and returns none. The deploy parameters of each deployment are left untouched: only the environment-secret manifest and the pod templates that read it are written. A browser session twin is mounted at the same path without the /api/v1 prefix (cookie authentication plus the X-Ankra-CSRF double-submit header).



## OpenAPI

````yaml https://platform.ankra.app/openapi.json post /api/v1/org/applications/{application_id}/env-secrets/apply
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
paths:
  /api/v1/org/applications/{application_id}/env-secrets/apply:
    post:
      tags:
        - Applications API
      summary: Apply Application Env Secrets
      description: >-
        Apply the application's stored environment secrets to what is already
        running: re-seal them into the Secrets the manifests read on every
        deployment and roll the workloads that read them. An application whose
        last key has been cleared applies too, and the apply then removes the
        sealed Secret from the deployment's stack and rolls the workloads off
        those values - without it, every reconcile put the deleted values back.
        The values only reach a running workload at deploy time otherwise, so
        this is the explicit one-click close of that gap - it is never triggered
        implicitly by setting a value. It takes no body (the values it applies
        are the ones already stored) and returns none. The deploy parameters of
        each deployment are left untouched: only the environment-secret manifest
        and the pod templates that read it are written. A browser session twin
        is mounted at the same path without the /api/v1 prefix (cookie
        authentication plus the X-Ankra-CSRF double-submit header).
      operationId: >-
        apply_application_env_secrets_api_v1_org_applications__application_id__env_secrets_apply_post
      parameters:
        - in: path
          name: application_id
          required: true
          schema:
            title: Application Id
            type: string
        - in: header
          name: authorization
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: Authorization
        - in: header
          name: x-ankra-organisation-id
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: X-Ankra-Organisation-Id
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplyApplicationEnvSecretsResponse'
          description: Successful Response
        '401':
          description: Unauthorized
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DemoDetailError'
          description: >-
            The member may not deploy this application, or (browser twin only)
            the CSRF check failed
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DemoDetailError'
          description: Not found ("Application not found")
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DemoDetailError'
          description: >-
            Nothing to apply to: the application is not deployed anywhere, every
            deployment of it is being removed, the organisation has no enabled
            SOPS configuration to seal the values with, or Ankra could not work
            out which Kubernetes Secret they belong in. An application with no
            environment secrets set is NOT refused - the apply removes the
            sealed Secret instead
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Validation Error
        '503':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DemoDetailError'
          description: >-
            The secret store, the encryptor or the stack-write lane is not
            available on this deployment of the platform
components:
  schemas:
    ApplyApplicationEnvSecretsResponse:
      description: >-
        The result of re-sealing an application's stored environment secrets
        into every deployment of it. No stored value appears in this model - the
        surface has no route that returns one.
      properties:
        revision:
          description: The catalogue revision this apply sealed.
          title: Revision
          type: string
        applied_count:
          title: Applied Count
          type: integer
        skipped_count:
          title: Skipped Count
          type: integer
        failed_count:
          title: Failed Count
          type: integer
        deployments:
          items:
            $ref: '#/components/schemas/ApplyApplicationEnvSecretOutcome'
          title: Deployments
          type: array
      required:
        - revision
        - applied_count
        - skipped_count
        - failed_count
        - deployments
      title: ApplyApplicationEnvSecretsResponse
      type: object
    DemoDetailError:
      description: >-
        The FastAPI-style detail envelope the demo routes use for
        400/403/404/409/502 responses.
      properties:
        detail:
          type: string
      required:
        - detail
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    ApplyApplicationEnvSecretOutcome:
      description: What one apply did to one deployment.
      properties:
        installation_id:
          title: Installation Id
          type: string
        cluster_id:
          title: Cluster Id
          type: string
        namespace:
          title: Namespace
          type: string
        status:
          description: >-
            "applied" - the deployment's stack now carries the current values,
            and the cluster reconcile rolls the stamped workloads onto them.
            "skipped" - a deploy of it is already running and seals the same
            values itself. "failed" - the apply could not reach it; see message.
          enum:
            - applied
            - skipped
            - failed
          title: Status
          type: string
        message:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            What there is to say about this deployment: the reason for a skip or
            a failure, or - on an apply that landed but rolled nothing - why.
            Never carries a stored value.
          title: Message
        rolled_workloads:
          description: >-
            How many pod templates this apply stamped, which is how many
            workloads Kubernetes restarts onto the new values. Zero on a landed
            apply means every workload already carried this revision, no
            workload reads the Secret, or the deployment has no rendered
            manifest to check; the last two say so in message.
          title: Rolled Workloads
          type: integer
      required:
        - installation_id
        - cluster_id
        - namespace
        - status
        - message
        - rolled_workloads
      title: ApplyApplicationEnvSecretOutcome
      type: object
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object

````