---
title: "Patch a deployment"
method: PATCH
path: "/v1/deployments/{dseq}"
tags: ["Deployments"]
---

# Patch a deployment

`PATCH /v1/deployments/{dseq}`

Patches the SDL the console stored for this deployment, or renames the deployment, or both; the SDL is never accepted from the request. Only the services named are touched. A `name` on its own touches no definition, so it renames a deployment the console holds no SDL for and sends neither a deployment update nor a manifest. Such a rename also reports every lease `status` as null, because it asks no provider for one. A patched environment variable is re-appended to its service's env list, so the order shown by GET may differ afterwards. A replaced secret takes effect through the deployment update this patch sends, not in the workload already running. The definition is recorded before the deployment update is sent, so an update that fails leaves the console describing a manifest version the deployment was never updated to. Re-sending the identical request repairs that: it recomputes the same manifest version, is accepted rather than refused, and goes on to send the update and push the manifest. A seal bound to the SDL is the exception: the first attempt replaced the SDL it was sealed against, so the same `sealedSecrets` answer 403 until the same values are sealed against the SDL GET now returns.

## Path parameters

- `dseq` string, required — Deployment sequence number

## Request body

- object
  - `data` object, required
    - `services` object — Keyed by service name. Only the named services are touched; omitted services keep their current definition. Omit it entirely to patch nothing about the definition, which is how a deployment is renamed on its own.
    - `name` string — Renames the deployment. Supplied on its own it is the only patch that touches no definition, so it works on a deployment the console holds no SDL for and sends neither a deployment update nor a manifest.
    - `sealedSecrets` string — Compact JWE sealing a flat name-to-value map, as on create, but holding only the names this patch replaces. Omitted names keep the values the deployment already stores. Its presence also says which values are secret, as on create: a patch carrying a seal stores the env values it writes as submitted, while one carrying none seals them. A seal of an empty map is how a caller writes plain variables without replacing any secret.
    - `ifManifestVersion` string — Base64 manifest version this patch expects to be current. Rejected with 409 if the deployment has moved on, unless it moved on to the version this very patch produces, which makes a retry of it succeed. Omitting this does not turn the guard off: the patch is then guarded on the version it read for itself, so a concurrent patch still answers 409 rather than overwriting it.

## Response `200`

Deployment patched successfully

- object
  - `data` object, required
    - `deployment` object, required
      - `id` object, required
        - `owner` string, required
        - `dseq` string, required
      - `state` string, required
      - `hash` string, required
      - `created_at` string, required
    - `leases` object[], required
      - `id` object, required
        - `owner` string, required
        - `dseq` string, required
        - `gseq` number, required
        - `oseq` number, required
        - `provider` string, required
        - `bseq` number, required
      - `state` string, required
      - `price` object, required
        - `denom` string, required
        - `amount` string, required
      - `created_at` string, required
      - `closed_on` string, required
      - `reason` string
      - `reclamation` object — Present only on a lease its provider has flagged for reclamation. `deadline` is unix seconds; `reason` is a `lease_closed_reason_*` enum name.
        - `window` string
        - `started_at` string
        - `deadline` string
        - `reason` string
      - `detectedGpus` object — GPUs the console observed running inside this lease's containers, as distinct from the models its group requested. Absent until the console has looked, and for a lease it cannot look inside.
        - `services` object[], required
          - `service` string, required
          - `gpus` object[], required
            - `vendor` string, nullable, required — Canonical vendor key, e.g. `nvidia`. Null for a card the console's model catalog does not list.
            - `model` string, nullable, required — Canonical SDL model key, e.g. `h100`. Null for a card the console's model catalog does not list.
            - `displayName` string, required — Marketing-correct label, e.g. `H100`, falling back to what the driver reported for an unlisted card.
            - `memoryMb` integer, required — Per-card memory as the driver reports it, in MiB.
            - `interface` string, nullable, required — `sxm` or `pcie` when the catalog names one, else null.
            - `count` integer, required — Identical cards folded into one entry.
        - `driverVersion` string, nullable, required
        - `detectedAt` string, date-time, required
      - `offeredGpus` object — GPUs the provider offered for this lease in the bid it was created from, which is what an `Any model` request resolves to. Absent until the console has recorded the bid, and for a lease whose deployment the console does not manage.
        - `gpus` object[], required
          - `vendor` string, required — Vendor key the provider offered, e.g. `nvidia`.
          - `model` string, required — SDL model key the provider offered, e.g. `a100`.
          - `displayName` string, required — Marketing-correct label for the model, e.g. `A100`.
          - `ram` string, nullable, required — Per-card memory, e.g. `80Gi`, when the offer names it. Providers name it only when the SDL asked for it.
          - `interface` string, nullable, required — `sxm` or `pcie` when the offer names it. Providers name it only when the SDL asked for it.
          - `count` integer, required — Cards of this model offered across every replica, identical ones folded into one entry.
        - `recordedAt` string, date-time, required
      - `status` object, nullable, required
        - `forwarded_ports` object, required
        - `ips` object, required
        - `services` object, required
    - `escrow_account` object, required
      - `id` object, required
        - `scope` string, required
        - `xid` string, required
      - `state` object, required
        - `owner` string, required
        - `state` string, required
        - `transferred` object[], required
          - `denom` string, required
          - `amount` string, required
        - `settled_at` string, required
        - `funds` object[], required
          - `denom` string, required
          - `amount` string, required
        - `deposits` object[], required
          - `owner` string, required
          - `height` string, required
          - `source` string, required
          - `balance` object, required
            - `denom` string, required
            - `amount` string, required
    - `name` string, nullable, required — The name this deployment carries, or null for one created before the console recorded names.
    - `manifestVersion` string — Base64 manifest version this patch recorded, which the deployment is now on. Absent for a rename, which records none.

## Other responses

- `400` — The patch names a service, port or volume the stored SDL does not declare, supplies a secret name it does not reference, leaves a reference with no value, moves a container port onto one the service already exposes, or moves a port in a way that would change its endpoint kind
- `403` — The `sealedSecrets` value was sealed for a different user, or bound to a different SDL than the one the console stores for this deployment, as a seal made before an earlier patch of it was recorded is
- `404` — No SDL is recorded for this deployment, so there is nothing to patch. A rename answers this only when the caller has no such deployment, since it needs no recorded SDL
- `409` — The deployment definition changed between this patch reading it and writing it. A patch naming no `ifManifestVersion` is guarded on the version it read, so a concurrent patch produces this too. Re-sending the identical patch is not a conflict, because the version it recomputes is the one the row already holds. `code` is `deployment_definition_changed` for this case, which a reload of the definition cures; a 409 without it answers a seal made against a retired key, which a fresh seal cures
- `422` — The SDL recorded for this deployment no longer declares the groups, compute resources, replica counts or globally exposed ports the deployment holds, as a full-SDL update can leave it: `code` is `deployment_resources_changed`, and nothing is recorded, no deployment update is sent and no provider is contacted
- `500` — The deployment's stored state could not be read: `code` is `stored_secrets_unreadable` when the sealed secrets would not open and `stored_sdl_unreadable` when the recorded SDL would not parse. Both are permanent rather than transient, so a retry cannot help, and both leave the stored token untouched. A 500 carrying any other `code` is an unexpected failure and promises neither of those things
- `503` — The key management service is temporarily unreachable. Transient and worth retrying, unlike the 500 above

## Changes

- **2026-09-25** `92586f3009d7` — 1 info
  - added the optional property `data/leases/items/offeredGpus` to the response with the `200` status
- **2026-09-24** `008c0988c96a` — 1 info
  - added the non-success response with the status `403`
- **2026-09-24** `d2bfd4f0bc0b` — 1 info
  - added the non-success response with the status `422`
- **2026-09-23** `26080d834862` — 2 info
  - added the new optional request property `data/services/additionalProperties/expose/additionalProperties/as`
  - added the new optional request property `data/services/additionalProperties/expose/additionalProperties/port`
- **2026-09-23** `4b7bb51509b3` — 1 info
  - added the optional property `data/leases/items/detectedGpus` to the response with the `200` status

[Full history](https://skmtc.dev/akash-network/apis/akash-network-console-api/changes/v1/deployments/:dseq/patch.md)

---

[API](https://skmtc.dev/akash-network/apis/akash-network-console-api.md) · [All operations](https://skmtc.dev/akash-network/apis/akash-network-console-api/llms.txt) · [OpenAPI document](https://skmtc.dev/akash-network/apis/akash-network-console-api/revisions/11865bf7bfb4?raw)
