> ## Documentation Index
> Fetch the complete documentation index at: https://docs.basaltic.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Scale or resize a load balancer

<Info>
  Requires the IAM action **`loadbalancer:UpdateLoadBalancer`**. See [LOADBALANCER permissions](/loadbalancer/permissions) for the full list, what each one covers, and an example policy.
</Info>


## OpenAPI

````yaml /api-reference/specs/loadbalancer.yaml patch /v1/load-balancers/{id}
openapi: 3.0.3
info:
  title: Basaltic Load Balancer API
  version: 1.0.0
  description: >
    Request relationships accept syntax-classified references resolved within
    the caller account and region.

    Floating IP references accept UUID or CRN only; IP targets stay literal.

    Managed load balancers: listeners, target pools, health checks and the

    TLS certificates a listener terminates.
  contact:
    name: Basaltic Support
    email: ping@basaltic.sh
  license:
    name: Proprietary
    url: https://basaltic.sh/terms
servers:
  - url: https://loadbalancer.{region}.basaltic.sh
    description: Regional API endpoint
    variables:
      region:
        default: sa-saopaulo-1
        description: Region code
security:
  - BearerAuth: []
paths:
  /v1/load-balancers/{id}:
    patch:
      tags:
        - Load Balancers
      summary: Scale or resize a load balancer
      operationId: updateLoadBalancer
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
            example: 4e1f8c2a-9b3d-4f6e-8a1c-2d5e7f9a0b3c
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateLoadBalancerRequest'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LoadBalancerResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  schemas:
    UpdateLoadBalancerRequest:
      additionalProperties: false
      type: object
      description: >
        Names are fixed at creation because they form the CRN used by IAM
        policies.

        Sending name in an update, including an unchanged, empty or null value,
        returns a validation error.
      properties:
        replica_count:
          type: integer
          minimum: 1
          maximum: 10
          example: 3
          description: |
            Resize the set of load balancer instances. Scale-out
            provisions the new replicas in sequence; scale-in removes
            the highest-indexed replicas best-effort. 1..10.
        flavor:
          type: string
          example: e5f6a7b8-c9d0-4123-e4f5-a6b7c8d9e0f1
          description: >
            Resize each replica to a different compute flavor. Must be a

            loadbalancer-family flavor.


            A running instance cannot change size in place, so the request
            records

            the new size and returns; the replicas already up are then replaced
            one

            at a time in the background. The load balancer temporarily runs one

            replica over replica_count while it does: the extra replica comes up
            on

            the new flavor and starts serving before any replica on the old one
            is

            retired, so the number serving never drops below replica_count — a

            resize does not cost you capacity, at any replica count.


            Expect it to take several minutes, and poll

            GET /v1/load-balancers/{id}/replicas to watch: a replica has been

            replaced when its instance_id changes, and the resize is done when

            every flavor there matches this one.


            The one exception is a load balancer already at the maximum of 10

            replicas, which has nowhere to grow. There the replicas are replaced
            in

            place and 9 serve while each replacement boots.


            Rejected up front if the account does not have the compute quota for

            the replacement replica, so a resize cannot half-apply and leave the

            load balancer short.
        tags:
          $ref: '#/components/schemas/Tags'
    LoadBalancerResponse:
      type: object
      properties:
        load_balancer:
          $ref: '#/components/schemas/LoadBalancer'
    Tags:
      type: object
      additionalProperties:
        type: string
      example:
        environment: production
        team: backend
    LoadBalancer:
      type: object
      required:
        - id
        - crn
        - account_id
        - name
        - type
        - status
        - faults
        - subnet
        - flavor_id
        - replica_count
        - tags
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
          example: 4e1f8c2a-9b3d-4f6e-8a1c-2d5e7f9a0b3c
        crn:
          type: string
          description: IAM resource CRN
          example: crn:loadbalancer:sa-saopaulo-1:my-account:load-balancer/web-lb
        account_id:
          type: string
          format: uuid
          example: 6f9619ff-8b86-4d01-b42d-00cf4fc964ff
        name:
          description: >-
            Resource names must not start with the literal crn: prefix or be
            UUIDs (canonical, compact, braced, or urn:uuid: forms, in either
            case).
          type: string
          example: web-lb
        type:
          type: string
          enum:
            - application
            - network
          description: ALB-shape (L7) vs NLB-shape (L4)
          example: application
        status:
          type: string
          enum:
            - provisioning
            - active
            - error
            - deleting
          example: active
        faults:
          type: array
          description: >-
            Active faults; status is error exactly when an active error fault
            remains.
          items:
            $ref: '#/components/schemas/Fault'
          example: []
        subnet:
          anyOf:
            - $ref: '#/components/schemas/Subnet'
            - type: object
              nullable: true
              enum:
                - null
          description: Subnet placement; null when the referenced subnet no longer exists.
        flavor_id:
          type: string
          format: uuid
          description: >-
            Compute flavor each LB instance runs on. Must be a
            loadbalancer-family flavor.
          example: e5f6a7b8-c9d0-4123-e4f5-a6b7c8d9e0f1
        replica_count:
          type: integer
          minimum: 1
          maximum: 10
          description: Number of LB compute instances. >=2 for HA.
          example: 2
        internal_ipv4:
          type: string
          description: >-
            Virtual IP for the load balancer; traffic is distributed to backends
            per connection.
          example: 203.0.113.50
        internal_ipv6:
          type: string
          description: Internal IPv6 VIP (set when the subnet is dual-stack).
          example: 2001:db8::32
        public_ipv6:
          type: string
          description: >-
            Public IPv6 address allocated from the regional pool and translated
            to the replica IPv6 addresses. Allocated best-effort for an
            internet-facing LB in a dual-stack subnet, including ULA subnets.
          example: 2a13:9500:1a6:101::a
        floating_ip_id:
          type: string
          format: uuid
          description: Optional FIP attached for public exposure. NULL ⇒ private-only LB.
          example: f6a7b8c9-d0e1-4234-f5a6-b7c8d9e0f1a2
        dns_name:
          type: string
          example: web-lb.my-account.lb.sa-saopaulo-1.basaltic.sh
          description: >-
            Convenience hostname auto-published for the load balancer,
            `{name}.{account-handle}.lb.{region}.{base-domain}`. Resolves to the
            floating IP on an internet-facing LB and to the private VIP
            otherwise. Omitted in regions where auto-DNS is not configured — the
            VIP and FIP stay authoritative either way.
        tags:
          $ref: '#/components/schemas/Tags'
        created_at:
          type: string
          format: date-time
          example: '2026-01-15T09:30:00Z'
        updated_at:
          type: string
          format: date-time
          example: '2026-01-15T09:30:00Z'
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - request_id
          properties:
            code:
              type: string
              description: Error code identifying the type of error
              example: INVALID_INPUT
            message:
              type: string
              description: Human-readable error message
              example: Invalid request parameters
            request_id:
              type: string
              format: uuid
              description: Request ID for debugging
              example: 550e8400-e29b-41d4-a716-446655440000
    Fault:
      type: object
      required:
        - code
        - severity
        - message
        - details
        - first_at
        - last_at
        - occurrences
      properties:
        code:
          type: string
          description: Stable machine-readable code owned by the reporting operation.
          example: BACKUP_FAILED
        severity:
          type: string
          enum:
            - error
            - warning
        message:
          type: string
          example: Backup upload failed.
        details:
          type: object
          nullable: true
          additionalProperties: true
          description: Structured context; legacy strings are preserved in legacy_text.
        first_at:
          type: string
          format: date-time
          description: First observation in this active occurrence series.
        last_at:
          type: string
          format: date-time
          description: Latest observation in this active occurrence series.
        occurrences:
          type: integer
          minimum: 1
          example: 1
    Subnet:
      type: object
      required:
        - id
        - crn
        - vpc
        - route_table
        - name
        - cidr_ipv4
        - gateway_ipv4
        - tags
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
          readOnly: true
        crn:
          type: string
          readOnly: true
          example: crn:network:sa-saopaulo-1:my-account:vpc/prod/subnet/prod-web
        vpc:
          $ref: '#/components/schemas/Vpc'
        route_table:
          $ref: '#/components/schemas/RouteTableSummary'
        name:
          description: >-
            Resource names must not start with the literal crn: prefix or be
            UUIDs (canonical, compact, braced, or urn:uuid: forms, in either
            case).
          type: string
          example: prod-web
        description:
          type: string
          example: Public web-tier subnet
        cidr_ipv4:
          type: string
          example: 10.0.1.0/24
        gateway_ipv4:
          type: string
          example: 10.0.1.1
        cidr_ipv6:
          type: string
          nullable: true
          readOnly: true
          description: >-
            The dual-stack IPv6 /64, if the subnet is v6-enabled. Its presence
            (vs the v4 cidr_ipv4) is how a client tells the subnet's families
            apart.
          example: 2a13:9500:1a6:100::/64
        gateway_ipv6:
          type: string
          nullable: true
          readOnly: true
          example: 2a13:9500:1a6:100::1
        tags:
          type: object
          additionalProperties:
            type: string
        created_at:
          type: string
          format: date-time
          readOnly: true
        updated_at:
          type: string
          format: date-time
          readOnly: true
    Vpc:
      type: object
      required:
        - id
        - crn
        - name
        - cidr_ipv4
        - tags
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
          readOnly: true
        crn:
          type: string
          readOnly: true
          description: Cloud Resource Name (name-based, region+account-scoped).
          example: crn:network:sa-saopaulo-1:my-account:vpc/prod
        name:
          type: string
          description: >-
            1-63 chars, lowercase alphanumeric + hyphen Resource names must not
            start with the literal crn: prefix or be UUIDs (canonical, compact,
            braced, or urn:uuid: forms, in either case).
          example: prod
        description:
          type: string
          example: Production VPC for web and app tiers
        cidr_ipv4:
          type: string
          description: >-
            IPv4 CIDR block carved up by subnets. Must be private (RFC 1918):
            within 10.0.0.0/8, 172.16.0.0/12 or 192.168.0.0/16. Immutable after
            create.
          example: 10.0.0.0/16
        cidr_ipv6:
          type: string
          nullable: true
          readOnly: true
          description: Associated regional GUA or private ULA prefix.
          example: 2a13:9500:1a6:100::/60
        tags:
          type: object
          additionalProperties:
            type: string
        created_at:
          type: string
          format: date-time
          readOnly: true
        updated_at:
          type: string
          format: date-time
          readOnly: true
    RouteTableSummary:
      type: object
      nullable: true
      additionalProperties: false
      description: |
        Route table used by a subnet, without repeating its VPC. Null when the
        non-owning lookup no longer resolves, for example during concurrent
        reassociation and deletion of the former table. Deleting a table still
        associated with subnets is refused.
      required:
        - id
        - crn
        - name
      properties:
        id:
          type: string
          format: uuid
          readOnly: true
        crn:
          type: string
          readOnly: true
          example: >-
            crn:network:sa-saopaulo-1:my-account:vpc/prod/route-table/prod-private-rt
        name:
          type: string
          example: prod-private-rt
  responses:
    BadRequest:
      description: Invalid request parameters
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INVALID_INPUT
              message: Invalid request parameters
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Unauthorized:
      description: Authentication required or token invalid
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: UNAUTHORIZED
              message: Authentication required
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Forbidden:
      description: Insufficient permissions
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: ACCESS_DENIED
              message: You don't have permission to perform this action
              request_id: 550e8400-e29b-41d4-a716-446655440000
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: NOT_FOUND
              message: Resource not found
              request_id: 550e8400-e29b-41d4-a716-446655440000
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: |
        An OAuth 2.0 bearer token, sent as `Authorization: Bearer <token>`.
        This is the recommended way to authenticate.

        Get one by exchanging a service account's access key pair at
        `POST /v1/oauth/token` with `grant_type=client_credentials`. It is the
        standard client-credentials grant, so any OAuth-aware library will
        obtain and refresh it for you.

        ```
        curl -s -u "$KEY_ID:$SECRET" -d grant_type=client_credentials \
          https://iam.basaltic.sh/v1/oauth/token
        ```

        Tokens last an hour by default. The same access key pair is separately
        your AWS SigV4 credential for the S3-compatible object endpoint, which
        speaks nothing else.

````