curl --request PATCH \
--url https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"health_check": {
"protocol": "http",
"path": "/healthz",
"port": 8080,
"interval_sec": 30,
"timeout_sec": 5,
"healthy_threshold": 3,
"unhealthy_threshold": 3,
"matcher": "200"
},
"proxy_protocol": true,
"tags": {
"environment": "production",
"team": "backend"
}
}
'import requests
url = "https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}"
payload = {
"health_check": {
"protocol": "http",
"path": "/healthz",
"port": 8080,
"interval_sec": 30,
"timeout_sec": 5,
"healthy_threshold": 3,
"unhealthy_threshold": 3,
"matcher": "200"
},
"proxy_protocol": True,
"tags": {
"environment": "production",
"team": "backend"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
health_check: {
protocol: 'http',
path: '/healthz',
port: 8080,
interval_sec: 30,
timeout_sec: 5,
healthy_threshold: 3,
unhealthy_threshold: 3,
matcher: '200'
},
proxy_protocol: true,
tags: {environment: 'production', team: 'backend'}
})
};
fetch('https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'health_check' => [
'protocol' => 'http',
'path' => '/healthz',
'port' => 8080,
'interval_sec' => 30,
'timeout_sec' => 5,
'healthy_threshold' => 3,
'unhealthy_threshold' => 3,
'matcher' => '200'
],
'proxy_protocol' => true,
'tags' => [
'environment' => 'production',
'team' => 'backend'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}"
payload := strings.NewReader("{\n \"health_check\": {\n \"protocol\": \"http\",\n \"path\": \"/healthz\",\n \"port\": 8080,\n \"interval_sec\": 30,\n \"timeout_sec\": 5,\n \"healthy_threshold\": 3,\n \"unhealthy_threshold\": 3,\n \"matcher\": \"200\"\n },\n \"proxy_protocol\": true,\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n }\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"health_check\": {\n \"protocol\": \"http\",\n \"path\": \"/healthz\",\n \"port\": 8080,\n \"interval_sec\": 30,\n \"timeout_sec\": 5,\n \"healthy_threshold\": 3,\n \"unhealthy_threshold\": 3,\n \"matcher\": \"200\"\n },\n \"proxy_protocol\": true,\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"health_check\": {\n \"protocol\": \"http\",\n \"path\": \"/healthz\",\n \"port\": 8080,\n \"interval_sec\": 30,\n \"timeout_sec\": 5,\n \"healthy_threshold\": 3,\n \"unhealthy_threshold\": 3,\n \"matcher\": \"200\"\n },\n \"proxy_protocol\": true,\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n }\n}"
response = http.request(request)
puts response.read_body{
"target_group": {
"id": "b8c9d0e1-f2a3-4456-b7c8-d9e0f1a2b3c4",
"crn": "crn:loadbalancer:sa-saopaulo-1:my-account:target-group/web-backends",
"account_id": "6f9619ff-8b86-4d01-b42d-00cf4fc964ff",
"name": "web-targets",
"protocol": "http",
"target_type": "instance",
"port": 8080,
"health_check": {
"protocol": "http",
"path": "/healthz",
"port": 8080,
"interval_sec": 30,
"timeout_sec": 5,
"healthy_threshold": 3,
"unhealthy_threshold": 3,
"matcher": "200"
},
"proxy_protocol": false,
"session_affinity": {
"type": "cookie",
"cookie_name": "BASALTICLB",
"duration_sec": 86400
},
"target_mode": "static",
"tags": {
"environment": "production",
"team": "backend"
},
"created_at": "2026-01-15T09:30:00Z",
"updated_at": "2026-01-15T09:30:00Z",
"instance_pool_id": "a1b2c3d4-e5f6-4789-a0b1-c2d3e4f5a6b7"
}
}{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "ACCESS_DENIED",
"message": "You don't have permission to perform this action",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "NOT_FOUND",
"message": "Resource not found",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}Update target group health checks, framing, or stickiness
curl --request PATCH \
--url https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"health_check": {
"protocol": "http",
"path": "/healthz",
"port": 8080,
"interval_sec": 30,
"timeout_sec": 5,
"healthy_threshold": 3,
"unhealthy_threshold": 3,
"matcher": "200"
},
"proxy_protocol": true,
"tags": {
"environment": "production",
"team": "backend"
}
}
'import requests
url = "https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}"
payload = {
"health_check": {
"protocol": "http",
"path": "/healthz",
"port": 8080,
"interval_sec": 30,
"timeout_sec": 5,
"healthy_threshold": 3,
"unhealthy_threshold": 3,
"matcher": "200"
},
"proxy_protocol": True,
"tags": {
"environment": "production",
"team": "backend"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
health_check: {
protocol: 'http',
path: '/healthz',
port: 8080,
interval_sec: 30,
timeout_sec: 5,
healthy_threshold: 3,
unhealthy_threshold: 3,
matcher: '200'
},
proxy_protocol: true,
tags: {environment: 'production', team: 'backend'}
})
};
fetch('https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'health_check' => [
'protocol' => 'http',
'path' => '/healthz',
'port' => 8080,
'interval_sec' => 30,
'timeout_sec' => 5,
'healthy_threshold' => 3,
'unhealthy_threshold' => 3,
'matcher' => '200'
],
'proxy_protocol' => true,
'tags' => [
'environment' => 'production',
'team' => 'backend'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}"
payload := strings.NewReader("{\n \"health_check\": {\n \"protocol\": \"http\",\n \"path\": \"/healthz\",\n \"port\": 8080,\n \"interval_sec\": 30,\n \"timeout_sec\": 5,\n \"healthy_threshold\": 3,\n \"unhealthy_threshold\": 3,\n \"matcher\": \"200\"\n },\n \"proxy_protocol\": true,\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n }\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"health_check\": {\n \"protocol\": \"http\",\n \"path\": \"/healthz\",\n \"port\": 8080,\n \"interval_sec\": 30,\n \"timeout_sec\": 5,\n \"healthy_threshold\": 3,\n \"unhealthy_threshold\": 3,\n \"matcher\": \"200\"\n },\n \"proxy_protocol\": true,\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://loadbalancer.{region}.basaltic.sh/v1/target-groups/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"health_check\": {\n \"protocol\": \"http\",\n \"path\": \"/healthz\",\n \"port\": 8080,\n \"interval_sec\": 30,\n \"timeout_sec\": 5,\n \"healthy_threshold\": 3,\n \"unhealthy_threshold\": 3,\n \"matcher\": \"200\"\n },\n \"proxy_protocol\": true,\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n }\n}"
response = http.request(request)
puts response.read_body{
"target_group": {
"id": "b8c9d0e1-f2a3-4456-b7c8-d9e0f1a2b3c4",
"crn": "crn:loadbalancer:sa-saopaulo-1:my-account:target-group/web-backends",
"account_id": "6f9619ff-8b86-4d01-b42d-00cf4fc964ff",
"name": "web-targets",
"protocol": "http",
"target_type": "instance",
"port": 8080,
"health_check": {
"protocol": "http",
"path": "/healthz",
"port": 8080,
"interval_sec": 30,
"timeout_sec": 5,
"healthy_threshold": 3,
"unhealthy_threshold": 3,
"matcher": "200"
},
"proxy_protocol": false,
"session_affinity": {
"type": "cookie",
"cookie_name": "BASALTICLB",
"duration_sec": 86400
},
"target_mode": "static",
"tags": {
"environment": "production",
"team": "backend"
},
"created_at": "2026-01-15T09:30:00Z",
"updated_at": "2026-01-15T09:30:00Z",
"instance_pool_id": "a1b2c3d4-e5f6-4789-a0b1-c2d3e4f5a6b7"
}
}{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "ACCESS_DENIED",
"message": "You don't have permission to perform this action",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "NOT_FOUND",
"message": "Resource not found",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}loadbalancer:UpdateTargetGroup. See LOADBALANCER permissions for the full list, what each one covers, and an example policy.Authorizations
An OAuth 2.0 bearer token, sent as Authorization: Bearer <token>.
This is the recommended way to authenticate.
Get one by exchanging a service account's access key pair at
POST /v1/oauth/token with grant_type=client_credentials. It is the
standard client-credentials grant, so any OAuth-aware library will
obtain and refresh it for you.
curl -s -u "$KEY_ID:$SECRET" -d grant_type=client_credentials \
https://iam.basaltic.sh/v1/oauth/token
Tokens last an hour by default. The same access key pair is separately your AWS SigV4 credential for the S3-compatible object endpoint, which speaks nothing else.
Path Parameters
UUID, CRN or exact account-scoped name
"b8c9d0e1-f2a3-4456-b7c8-d9e0f1a2b3c4"
Body
Names are fixed at creation because they form the CRN used by IAM policies. Sending name in an update, including an unchanged, empty or null value, returns a validation error.
Show child attributes
Show child attributes
Toggle PROXY v2 framing on upstream connections. Omitting the field leaves the current setting; setting true/false flips it explicitly.
Replaces the stickiness config. Omitting the field leaves it alone; turning it off is an explicit {"type": "none"}.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
{
"environment": "production",
"team": "backend"
}
Response
OK
Show child attributes
Show child attributes