delete_tier1_gateway
Delete a Tier-1 gateway safely: first previews the blast radius of affected resources, then removes the gateway only when no segments, NAT, routes, or services depend on it.
Instructions
[WRITE] Delete a Tier-1 gateway; refuses while anything still depends on it.
Irreversible. Without confirm=True this only previews: it returns blast_radius (name, tier0_path, the "default" locale-service and edge cluster the delete removes, dependents by kind, blockers, unmeasured) and deletes nothing. Show that to the user and get their decision. Do not set confirm=True on your own because the user asked to delete earlier: they have not seen the blast radius yet.
confirm=True re-measures (read-only) and refuses, deleting nothing, while any remain: attached segments or Tier-1-scoped segments, NAT rules, static routes, service interfaces, extra locale-services, IPsec/L2 VPN services, a DNS forwarder, or a load balancer service attached to it — or when any of them could not be read. It never removes them for you. When clear, deletes the "default" locale-service, then the gateway. Returns {"action": "preview" | "deleted", "blast_radius": ...}, else {"error", "hint", "blast_radius"?}.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | No | NSX Manager target from config (default if omitted). | |
| confirm | No | False (default) returns the blast radius and changes nothing. True applies it. | |
| tier1_id | Yes | Gateway ID to delete, as returned by list_tier1_gateways. |