Alert Rules (Write)

Engineer or admin CRUD for alert rules. Alert rules define conditions that trigger alert instances when matching topology events occur.

Seeded system alert rules (created by migrations, can be toggled/edited by admins):

Create Alert Rule

POST /api/v1/alerts/rules

Request body:

{
  "name": "Link Down",
  "description": "Alert when a link goes down",
  "severity": "critical",
  "event_type": "link_state_changed",
  "condition": {"state": "down"},
  "scope_type": "area",
  "scope_id": "uuid",
  "enabled": true,
  "cooldown_secs": 600
}

Validation:

Response: 201 Created

{
  "id": "uuid",
  "name": "Link Down",
  "description": "Alert when a link goes down",
  "severity": "critical",
  "event_type": "link_state_changed",
  "condition": {"state": "down"},
  "scope_type": "area",
  "scope_id": "uuid",
  "enabled": true,
  "cooldown_secs": 600,
  "created_by": "uuid",
  "created_at": "2026-02-17T12:00:00Z",
  "updated_at": "2026-02-17T12:00:00Z"
}

Error responses:

Get Alert Rule

GET /api/v1/alerts/rules/{ruleID}

Get a single alert rule by ID.

Response: 200 OK (single alert rule object)

Error responses:

Update Alert Rule

PUT /api/v1/alerts/rules/{ruleID}

Partial update of an alert rule. Uses read-merge-write -- only fields present in the request body are updated; other fields are preserved.

Request body (all fields optional):

{
  "name": "Updated Rule Name",
  "description": "Updated description",
  "severity": "warning",
  "event_type": "device_removed",
  "condition": {"new_condition": true},
  "scope_type": "protocol_instance",
  "scope_id": "uuid",
  "enabled": false,
  "cooldown_secs": 120
}

Response: 200 OK (updated alert rule object)

Error responses:

Delete Alert Rule

DELETE /api/v1/alerts/rules/{ruleID}

Delete an alert rule.

Response: 204 No Content

Error responses:

Toggle Alert Rule

POST /api/v1/alerts/rules/{ruleID}/toggle

Flip the enabled flag on an alert rule. If the rule is currently enabled, it becomes disabled, and vice versa.

Response: 200 OK (updated alert rule object with toggled enabled field)

Error responses:

List Rule Notification Channels

GET /api/v1/alerts/rules/{ruleID}/channels

Returns notification channels linked to this alert rule, including the notify_on setting for each.

Response: 200 OK

[
  {
    "channel_id": "uuid",
    "channel_name": "Slack Ops",
    "channel_type": "slack",
    "notify_on": "both",
    "enabled": true
  }
]

Set Rule Notification Channels

PUT /api/v1/alerts/rules/{ruleID}/channels

Replaces all notification channel links for an alert rule. Existing links are removed and replaced with the provided list.

Request body:

[
  { "channel_id": "uuid-1", "notify_on": "both" },
  { "channel_id": "uuid-2", "notify_on": "firing" }
]

Response: 200 OK (updated list of linked channels)

Error responses: