Skip to content
Helicarrier Developers

Set read-only filesystem

Configure a read-only root filesystem for the service’s next deployment.

PATCH /api/services/{id}/security HTTPS
Request & response examples
Request example Server-side
curl --fail-with-body --request PATCH \
'https://app.helicarrier.xyz/api/services/YOUR_ID/security' \
-H "Authorization: Bearer $HELI_API_KEY" \
-H 'Content-Type: application/json' \
--data '{
"readonlyRootfs": true
}'
Response example 200
{
"readonlyRootfs": true,
"appliesAt": "next deploy"
}

Illustrative values · selected fields

Authorization

An account key with access, or a project/service key with settings:write. The resource must be within the key’s project, service, and environment scope.

Authorization: Bearer <key> Key setup ↗

Path parameters

id string required

Service id.

Request body

readonlyRootfs boolean required

true to mount the root filesystem read-only, false to restore a writable one.

Response 200

Returns the saved filesystem setting and when it takes effect. Redeploy the service to apply it.

Examples show selected response fields with illustrative values. Your response can contain additional fields.

readonlyRootfs boolean

Whether the root filesystem is read-only.

appliesAt string

When the saved setting applies.

Errors

400

Invalid parameters. Check the required fields, types, and resource configuration.

401

The API key is missing, invalid, or revoked.

403

The caller or key scope does not permit this operation.

500

The operation could not be completed. Check resource state before retrying a write.

Error handling and safe retries
ALSO AVAILABLE VIA MCP

set_readonly_filesystem

Required MCP arguments: id, readonlyRootfs. Send path, query, and body fields together as tool arguments.

Connect your agent ↗