---
title: "Update a subnet"
method: PUT
path: "/api/v1/subnets/{id}"
tags: ["Subnets"]
---

# Update a subnet

`PUT /api/v1/subnets/{id}`

Updates subnet properties. If the CIDR is being changed, validates that
all existing ip_addresses on this subnet have IPs within the new CIDR range.

## Path parameters

- `id` string, uuid, required

## Request body

- Subnet
  - `cidr` string, required — Subnet in CIDR notation, IPv4 or IPv6.
  - `description` string, nullable — Free-text notes about the subnet.
  - `name` string, required — Human-facing name for this subnet.
  - `network_id` string, uuid, required — The network this entity belongs to.
  - `source` union, required
    - object
      - `type` 'Manual', required
    - object
      - `type` 'System', required
    - object
      - `type` 'Discovery', required
    - object
      - `details` MatchDetails, required
        - `confidence` 'NotApplicable' | 'Low' | 'Medium' | 'High' | 'Certain', required
        - `reason` union, required — Match reason - either a simple reason string or a container with nested reasons
          - object
            - `data` string, required — Why the service was matched.
            - `type` 'reason', required
          - object
            - `data` unknown[], required — Tuple of [name: string, children: MatchReason[]]
              - …
            - `type` 'container', required
      - `type` 'DiscoveryWithMatch', required
    - object
      - `type` 'Unknown', required
  - `subnet_type` 'Internet' | 'Remote' | 'Gateway' | 'VpnTunnel' | 'Dmz' | 'Lan' | 'WiFi' | 'IoT' | 'Guest' | 'DockerBridge' | 'PodmanBridge' | 'MacVlan' | 'IpVlan' | 'Management' | 'Storage' | 'Loopback' | 'Unknown', required
  - `tags` string[], required — Tags assigned to this entity.
  - `virtualization_service_id` string, uuid, nullable, required — The container runtime service that owns this bridge network. Load-bearing for dedup: the same CIDR on two different Docker daemons is two distinct subnets, so bridge rows only merge when this matches as well as the CIDR and network. A foreign key rather than a field inside a JSONB blob because a stale value here is precisely what made a scan add a duplicate bridge row every time (GH #650) — now it cannot be written at all.
  - `created_at` string, date-time, required — When this record was first created.
  - `first_discovery_id` string, uuid, nullable — The discovery that first observed this entity.
  - `id` string, uuid, required — Server-assigned unique identifier.
  - `last_discovery_id` string, uuid, nullable — The most recent discovery that observed this entity.
  - `last_seen_at` string, date-time — When a discovery last observed this entity.
  - `lineage_id` string, uuid, nullable — Stable identifier shared by every revision of the same entity across its history.
  - `updated_at` string, date-time, required — When this record was last modified.
  - `valid_from` string, date-time — Start of the interval this revision was current for (SCD2 history).
  - `valid_to` string, date-time, nullable — End of the interval this revision was current for. `null` while it is the live revision.

## Response `200`

Subnet updated

- ApiResponseSubnet
  - `data` object — The result payload. Omitted on failure.
    - `cidr` string, required — Subnet in CIDR notation, IPv4 or IPv6.
    - `description` string, nullable — Free-text notes about the subnet.
    - `name` string, required — Human-facing name for this subnet.
    - `network_id` string, uuid, required — The network this entity belongs to.
    - `source` union, required
      - object
        - `type` 'Manual', required
      - object
        - `type` 'System', required
      - object
        - `type` 'Discovery', required
      - object
        - `details` MatchDetails, required
          - `confidence` 'NotApplicable' | 'Low' | 'Medium' | 'High' | 'Certain', required
          - `reason` union, required — Match reason - either a simple reason string or a container with nested reasons
            - object
              - …
            - object
              - …
        - `type` 'DiscoveryWithMatch', required
      - object
        - `type` 'Unknown', required
    - `subnet_type` 'Internet' | 'Remote' | 'Gateway' | 'VpnTunnel' | 'Dmz' | 'Lan' | 'WiFi' | 'IoT' | 'Guest' | 'DockerBridge' | 'PodmanBridge' | 'MacVlan' | 'IpVlan' | 'Management' | 'Storage' | 'Loopback' | 'Unknown', required
    - `tags` string[], required — Tags assigned to this entity.
    - `virtualization_service_id` string, uuid, nullable, required — The container runtime service that owns this bridge network. Load-bearing for dedup: the same CIDR on two different Docker daemons is two distinct subnets, so bridge rows only merge when this matches as well as the CIDR and network. A foreign key rather than a field inside a JSONB blob because a stale value here is precisely what made a scan add a duplicate bridge row every time (GH #650) — now it cannot be written at all.
    - `created_at` string, date-time, required — When this record was first created.
    - `first_discovery_id` string, uuid, nullable — The discovery that first observed this entity.
    - `id` string, uuid, required — Server-assigned unique identifier.
    - `last_discovery_id` string, uuid, nullable — The most recent discovery that observed this entity.
    - `last_seen_at` string, date-time — When a discovery last observed this entity.
    - `lineage_id` string, uuid, nullable — Stable identifier shared by every revision of the same entity across its history.
    - `updated_at` string, date-time, required — When this record was last modified.
    - `valid_from` string, date-time — Start of the interval this revision was current for (SCD2 history).
    - `valid_to` string, date-time, nullable — End of the interval this revision was current for. `null` while it is the live revision.
  - `error` string, nullable — Human-readable failure message. Omitted on success.
  - `meta` ApiMeta, required — API metadata included in all responses
    - `api_version` integer, required — API version (integer, increments on breaking changes)
    - `server_version` string, required — Server version (semver)
  - `success` boolean, required — `true` when the request succeeded. `false` responses carry `error` instead of `data`.

## Other responses

- `400` — CIDR change would orphan existing ip_addresses
- `404` — Subnet not found

---

[API](https://skmtc.net/scanopy/apis/scanopy-api.md) · [All operations](https://skmtc.net/scanopy/apis/scanopy-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/scanopy/scanopy-api/versions/28e466341947/schema)
