---
title: "Record the definition of a deployment the console holds none for"
method: POST
path: "/v1/deployments/{dseq}/definition"
tags: ["Deployments"]
---

# Record the definition of a deployment the console holds none for

`POST /v1/deployments/{dseq}/definition`

Records the SDL of a deployment the console holds no definition for, such as one created before the console recorded definitions or created outside it. The SDL and its sealed secrets are taken as on create, and the secrets are stored the same way. The SDL is recorded only if it resolves to the manifest version the deployment already runs, so recording sends no deployment update and no manifest, and a closed deployment can be given its definition too. Afterwards the deployment reads back and takes patches like any other. To apply an SDL that differs from what the deployment runs, update the deployment with it instead.

## Path parameters

- `dseq` string, required — Deployment sequence number

## Request body

- object
  - `data` object, required
    - `sdl` string, required
    - `sealedSecrets` string — Compact JWE sealing a flat name-to-value map of the secrets this SDL references, encrypted to the console's public sealing key. Fetch that key and the claims to sign from GET /v1/sdl-secrets-context. Values are never returned by any endpoint once sealed.

## Response `201`

The definition was recorded, as GET /v1/deployments/{dseq} now returns it

- object
  - `data` object, required
    - `sdl` string, required — The SDL the console stored for this deployment. Re-serialized YAML, so not byte-identical to the submitted document.
    - `manifestVersion` string, required — Base64 of the manifest version the console recorded for this deployment. Deliberately not a hash of the `sdl` above.

## Other responses

- `400` — The SDL is not valid, leaves a secret reference with no value from `sealedSecrets`, supplies a name no service references, or carries a `sealedSecrets` value that is malformed, tampered with, expired or not a flat object of string values
- `403` — The `sealedSecrets` value was sealed for a different user, or bound to a different SDL than the one submitted
- `404` — No deployment of yours matches `dseq`
- `409` — With `code` `deployment_definition_exists`, the console already holds a definition for this deployment, which this route never replaces: patch it instead. Without a code, the `sealedSecrets` value was sealed to a key the console no longer holds, so refetch `GET /v1/sdl-secrets-context` and seal again
- `422` — The SDL does not resolve to the manifest version the deployment runs: `code` is `deployment_definition_mismatch`, and nothing is recorded. Update the deployment to apply it instead
- `503` — The key management service, or the version the deployment runs, could not be read. Transient and worth retrying

## Changes

- **2026-09-25** `87b71610b061` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/akash-network/apis/akash-network-console-api/changes/v1/deployments/:dseq/definition/post.md)

---

[API](https://skmtc.dev/akash-network/apis/akash-network-console-api.md) · [All operations](https://skmtc.dev/akash-network/apis/akash-network-console-api/llms.txt) · [OpenAPI document](https://skmtc.dev/akash-network/apis/akash-network-console-api/revisions/11865bf7bfb4?raw)
