> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Add service

> **Token scope:** `account` · `org` · `project` — read-only tokens refused (not a GET).

Add a service on demand. Assigns a default access domain (postgres/compute). Gated — service.add.



## OpenAPI

````yaml /openapi/project.json post /projects/{projectId}/services
openapi: 3.1.0
info:
  title: InstaCloud API — Project level
  version: 0.1.0
  description: >-
    Endpoints under `/projects/{projectId}`: branches, services, deploys,
    secrets, databases, storage, cron, observability, governance. Callable with
    any token whose binding covers the project.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Projects
    description: Projects inside an organization.
  - name: Branches
    description: >-
      Branch environments of a project: isolated database, storage and compute
      per branch.
  - name: Services
    description: 'Services on a branch: compute, postgres, storage and managed databases.'
  - name: Deploy
    description: Deploy an image or a source to a compute service.
  - name: Compute
    description: Build output of a compute service.
  - name: Secrets
    description: User secrets, service credentials and how they bind into compute env.
  - name: Database
    description: Postgres databases, extensions, credentials and ad-hoc SQL.
  - name: Storage
    description: Objects in a storage service.
  - name: Backups
    description: Database backups and restores.
  - name: Cron
    description: Scheduled HTTP calls against a service or an external URL.
  - name: Observability
    description: Logs, metrics, deploy events and database insight.
  - name: Governance
    description: Per-project agent policy and the approval queue.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
  - name: Templates
    description: Deploy a template into a project.
paths:
  /projects/{projectId}/services:
    post:
      tags:
        - Services
      summary: Add service
      description: >-
        **Token scope:** `account` · `org` · `project` — read-only tokens
        refused (not a GET).


        Add a service on demand. Assigns a default access domain
        (postgres/compute). Gated — service.add.
      operationId: addService
      parameters:
        - schema:
            format: uuid
            type: string
          in: path
          name: projectId
          required: true
      requestBody:
        content:
          application/json:
            schema:
              required:
                - type
                - name
              type: object
              properties:
                type:
                  anyOf:
                    - type: string
                      enum:
                        - postgres
                    - type: string
                      enum:
                        - storage
                    - type: string
                      enum:
                        - compute
                    - type: string
                      enum:
                        - redis
                    - type: string
                      enum:
                        - mysql
                    - type: string
                      enum:
                        - mongodb
                name:
                  description: 'lower-kebab: a-z, 0-9, hyphen'
                  type: string
                branch:
                  description: 'target branch (default: project default branch)'
                  type: string
                region:
                  description: >-
                    region for postgres/compute/managed databases (see GET
                    /regions); invalid for storage
                  anyOf:
                    - type: string
                      enum:
                        - us-east
                    - type: string
                      enum:
                        - eu-central
                    - type: string
                      enum:
                        - ap-southeast
                public:
                  description: >-
                    storage only — provision the bucket with anonymous
                    public-read (default false)
                  type: boolean
                image:
                  description: >-
                    compute only — container image to run at creation (e.g.
                    nginx:1.27)
                  type: string
                port:
                  description: compute only — port the image listens on (default 8080)
                  type: integer
                alwaysOn:
                  description: >-
                    compute only — idle mode at creation. Omitted: the platform
                    default (INSTA_COMPUTE_ALWAYS_ON_DEFAULT; true on
                    InstaCloud: machines never scale to zero). false =
                    scale-to-zero: idle machines suspend and wake on request.
                    All plans; billing is actual usage either way.
                  type: boolean
                volumeMountPath:
                  description: >-
                    Compute only: container mount path chosen on attachment;
                    defaults to /data. Requires volumeGib only when attaching.
                    Existing path changes are staged until the next deploy.
                  type: string
                volumeGib:
                  minimum: 1
                  description: >-
                    compute only — attach a persistent volume of this many whole
                    Gi (attachable later too via PUT /services/:id/volume; the
                    volume never detaches, but DELETE /services/:id/volume
                    destroys it, data and all). Any plan may create up to the
                    configured free volume cap (10Gi by default, env-overridable
                    per deployment); a larger size is paid and capped at the
                    org's own plan cap (50Gi on paid plans by default), like
                    growing it later. Constraints: machineCount stays 1, and
                    scale-to-zero uses stop (cold wake) instead of suspend —
                    both lift if the volume is deleted.
                  type: integer
                source:
                  required:
                    - owner
                    - repo
                  type: object
                  properties:
                    type:
                      type: string
                      enum:
                        - github
                    owner:
                      type: string
                    repo:
                      type: string
                    installationId:
                      description: GitHub App installation id; required unless public
                      type: integer
                    repoId:
                      description: GitHub repository id; required unless public
                      type: integer
                    public:
                      description: >-
                        a public repo, connected without an App installation:
                        one-shot deploys, auto_deploy is always false
                      type: boolean
                    branch:
                      description: >-
                        the repo branch to track; default: the repo’s default
                        branch
                      type: string
                    rootDir:
                      description: >-
                        subdirectory to build from (monorepo); relative, no
                        leading / or ..; null/omitted = repo root. It also
                        decides which pushes deploy this service: the build
                        context is this directory, so a push that changed
                        nothing under it is skipped
                      anyOf:
                        - type: string
                        - type: 'null'
                    autoDeploy:
                      description: >-
                        rebuild on every push to `branch` (default true; must be
                        false or omitted for a public repo)
                      type: boolean
                    buildCommand:
                      anyOf:
                        - type: string
                        - type: 'null'
                    startCommand:
                      anyOf:
                        - type: string
                        - type: 'null'
                    watchPaths:
                      description: >-
                        An include list of gitignore patterns, matched against
                        paths RELATIVE TO THE REPOSITORY ROOT rather than to
                        `rootDir` — e.g. ["apps/web/**", "packages/ui/**"]. A
                        push deploys this service only when it changed a
                        matching path; omit or null to fall back to the
                        root-directory rule (a service with `rootDir` deploys
                        when a push changed something under it, one building
                        from the repo root deploys on every push). `!` narrows
                        the list under git's own rule that a path cannot be
                        re-included once an earlier pattern took its directory,
                        so ["apps/web/**", "!**/*.md"] drops apps/web/README.md
                        but not apps/web/docs/guide.md. Inert on a public repo,
                        which cannot auto-deploy at all
                      anyOf:
                        - type: array
                          items:
                            type: string
                        - type: 'null'
                    port:
                      description: the port the app listens on; written to the service
                      anyOf:
                        - minimum: 1
                          maximum: 65535
                          type: integer
                        - type: 'null'
        required: true
      responses:
        '201':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  service:
                    $ref: '#/components/schemas/Service'
                  source:
                    $ref: '#/components/schemas/ServiceSource'
                  build:
                    type: object
                    properties:
                      buildId:
                        format: uuid
                        type: string
                      queued:
                        description: false when this commit already has a build (dedup)
                        type: boolean
                      serviceId:
                        format: uuid
                        type: string
                    required:
                      - buildId
                      - queued
                      - serviceId
                  nextActions:
                    type: array
                    items:
                      $ref: '#/components/schemas/NextAction'
        '202':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApprovalRequired'
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '409':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '502':
          description: >-
            the provider could not provision the service — nothing was created;
            safe to retry
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                description: >-
                  the provider could not provision the service — nothing was
                  created; safe to retry
components:
  schemas:
    Service:
      description: >-
        A project-level service (postgres | storage | compute | redis | mysql |
        mongodb).
      type: object
      properties:
        id:
          format: uuid
          type: string
        project_id:
          format: uuid
          type: string
        type:
          type: string
          enum:
            - postgres
            - storage
            - compute
            - redis
            - mysql
            - mongodb
        name:
          type: string
        spec:
          description: >-
            compute: {cpu_kind,cpus,memory_mb}; postgres: sized by its instance
            ceiling (cpuMilli/memoryMib)
          type: object
          additionalProperties: true
        machine_count:
          description: compute only
          type: integer
        desired_state:
          description: compute only — developer-set lifecycle intent
          type: string
          enum:
            - running
            - stopped
            - suspended
        always_on:
          description: >-
            compute only — true (the platform default for new compute services):
            machines never scale to zero; false: idle machines suspend and wake
            on request. Billing is actual usage either way.
          type: boolean
        websocket:
          description: >-
            compute only — the app speaks WebSocket, so its machines carry
            connections-based concurrency and a 512 MB guest floor. Re-asserted
            by any redeploy given no flag, including restart. null: never
            recorded.
          type:
            - boolean
            - 'null'
        region:
          type:
            - string
            - 'null'
        domain:
          description: default access domain (postgres/compute)
          type:
            - string
            - 'null'
        public:
          description: storage only — bucket(s) served with anonymous public-read
          type: boolean
        image:
          description: compute only — container image currently run
          type:
            - string
            - 'null'
        port:
          description: >-
            compute/managed database — compute image port, or the private
            database TCP port
          type:
            - integer
            - 'null'
        start_command:
          description: >-
            Runtime startup override via sh -c; null uses the built image
            default. Stored as readable service settings.
          type:
            - string
            - 'null'
        volume_applied_mount_path:
          description: >-
            Last successfully confirmed Compute mount path; null means unknown,
            not proof of a changed path.
          type:
            - string
            - 'null'
        volume_mount_path:
          description: >-
            Compute volume mount path; null or omitted means /data for legacy
            volumes. Changes apply on deployment.
          type:
            - string
            - 'null'
        volume_gib:
          description: >-
            compute/managed database — size (whole Gi) of the persistent data
            volume; null = no volume. Compute can attach/grow via PUT
            .../volume; managed databases are platform-managed in v1
          type:
            - integer
            - 'null'
        pg_version:
          description: >-
            postgres only — the Postgres MAJOR version the service runs (e.g.
            16), known before the instance is ever connected to or woken. Pick
            client tooling (pg_dump/pg_restore/psql) of the same major. null:
            never recorded (a legacy row). The exact server_version of a RUNNING
            instance is on GET .../database/metrics
          type:
            - integer
            - 'null'
        template_deployment_id:
          format: uuid
          description: >-
            the template deployment that created this service (survives branch
            clones); null for services created directly
          type:
            - string
            - 'null'
        template_modified:
          description: >-
            true once the service was reconfigured away from its
            template-deployed spec
          type: boolean
        template_code:
          description: >-
            the template this service was deployed from; null for services
            created directly, and for one whose deployment record has been
            pruned
          type:
            - string
            - 'null'
        template_logo_url:
          description: >-
            the template's mark, absolute and pinned to the commit that
            published it; null when the template is not in the registry (or
            carries no logo). Joined live rather than stored, because a
            republish moves it
          type:
            - string
            - 'null'
        source:
          $ref: '#/components/schemas/ServiceSourceSummary'
        status:
          type: string
          enum:
            - creating
            - active
            - error
            - deleting
            - deleted
        created_at:
          format: date-time
          type: string
    ServiceSource:
      description: >-
        Where a compute service’s running image comes from: an image somebody
        deployed (type=image, the absence of a connected source) or a connected
        repository (type=github).
      type: object
      properties:
        type:
          type: string
          enum:
            - image
            - github
        image:
          description: >-
            type=image — the image the service runs; null when nothing has been
            deployed yet
          type:
            - string
            - 'null'
        id:
          format: uuid
          type: string
        owner:
          type: string
        repo:
          type: string
        branch:
          description: >-
            the repo branch this service tracks; defaults to the repo’s default
            branch
          type: string
        root_dir:
          description: >-
            subdirectory to build from (monorepo); null = repo root. Also
            decides which pushes deploy this service: the build context is this
            directory, so a push that changed nothing under it is skipped
          type:
            - string
            - 'null'
        watch_paths:
          description: >-
            include list of gitignore patterns, matched against paths relative
            to the repository root (not to root_dir); a push deploys this
            service only when it changed a matching path. null/absent falls back
            to the root-directory rule: a service with root_dir deploys when a
            push changed something under it, one building from the repo root
            deploys on every push
          type:
            - array
            - 'null'
          items:
            type: string
        auto_deploy:
          description: >-
            a push to `branch` rebuilds and redeploys; always false for a public
            repo (no App, no webhooks)
          type: boolean
        public:
          description: connected as a public repo, without a GitHub App installation
          type: boolean
        installation_id:
          format: uuid
          type:
            - string
            - 'null'
        repo_id:
          description: GitHub repository id (bigint as string)
          type:
            - string
            - 'null'
        build_command:
          description: >-
            custom build command for source builds without a Dockerfile; null
            uses automatic detection
          type:
            - string
            - 'null'
        start_command:
          type:
            - string
            - 'null'
        created_at:
          format: date-time
          type: string
        updated_at:
          format: date-time
          type: string
        last_build:
          anyOf:
            - allOf:
                - $ref: '#/components/schemas/ServiceBuild'
            - type: 'null'
          description: the newest build of this service (null before the first)
      required:
        - type
    NextAction:
      type: object
      properties:
        op:
          description: >-
            Neutral logical action id, e.g. "service.add" — NOT an operationId
            or a CLI/MCP tool name; each client maps it to its own surface.
          type: string
        reason:
          description: Natural-language, human/LLM-facing "why do this now".
          type: string
        args:
          description: >-
            Suggested, flat named arguments; "<placeholder>"s where a value is
            unknown.
          type: object
          additionalProperties: true
        gated:
          description: True if the action passes a governance gate.
          type: boolean
      required:
        - op
        - reason
    ApprovalRequired:
      type: object
      properties:
        status:
          type: string
          enum:
            - approval_required
        approvalId:
          format: uuid
          type: string
        action:
          description: the gated action, or a comma-joined compound set — prefer `actions`
          type: string
        actions:
          description: every capability this approval covers
          type: array
          items:
            type: string
        message:
          type: string
        url:
          description: the console page where a project admin reviews this request
          type: string
        nextActions:
          type: array
          items:
            $ref: '#/components/schemas/NextAction'
    Error:
      type: object
      properties:
        error:
          type: string
      required:
        - error
    ServiceSourceSummary:
      description: >-
        compute only — where the running image comes from: an image somebody
        deployed (type=image) or a connected repository (type=github). Full
        resource: GET /projects/{id}/services/{serviceId}/source
      type: object
      properties:
        type:
          type: string
          enum:
            - image
            - github
        owner:
          type: string
        repo:
          type: string
        branch:
          description: the repo branch this service tracks
          type: string
        auto_deploy:
          description: a push to `branch` rebuilds and redeploys the service
          type: boolean
      required:
        - type
    ServiceBuild:
      description: >-
        One build → image → deploy attempt of a service source (one per commit
        per source).
      type: object
      properties:
        id:
          format: uuid
          type: string
        source_id:
          format: uuid
          description: >-
            the service source that queued it; null once that source was
            disconnected
          type:
            - string
            - 'null'
        repo_binding_id:
          format: uuid
          description: >-
            DEPRECATED — set only on builds queued before sources existed; null
            for every new build
          type:
            - string
            - 'null'
        project_id:
          format: uuid
          type: string
        service_id:
          format: uuid
          type:
            - string
            - 'null'
        branch_id:
          format: uuid
          type:
            - string
            - 'null'
        commit_sha:
          type: string
        status:
          type: string
          enum:
            - queued
            - fetching
            - building
            - deploying
            - live
            - failed
        image_ref:
          type:
            - string
            - 'null'
        error:
          type:
            - string
            - 'null'
        created_at:
          format: date-time
          type: string
        updated_at:
          format: date-time
          type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````