← CCNP Enterprise: ENCOR core and operations
22 / 22 · 65 MIN

RESTCONF: versions, types and concurrent updates

Interpret requests and responses, preserve concurrent changes, and distinguish syntax from validity and outcome.

The contract includes the model

Valid JSON is only the first check. The model defines names, types, keys, mandatory content and relationships. For a YANG boolean field, false is Boolean while "false" is text. Other types have their own rules: RFC 7951 encodes int64 and uint64 as JSON strings to preserve values, so converting every number into a JSON number is also wrong. Record the module revision and target capabilities. In an interface payload, verify that the body key matches the resource key. This lesson’s lab has a small handwritten schema requiring name and enabled; those are exercise requirements rather than a complete description of ietf-interfaces.

Change scope depends on the request

PUT creates or replaces the target resource. Sending only part of a complex resource can remove omitted optional configuration or activate model-defined defaults. Choose the target carefully and compare the intended result before sending. A RESTCONF plain patch merges; YANG Patch uses another media type and an ordered list of edits to express more precise decisions. Do not send one format’s body with another format’s Content-Type. Inspect supported formats, for example through Accept-Patch where applicable. A sequence of separate HTTP requests does not gain collective atomicity merely because every step uses PATCH.

Concurrency between two reads

Two operators read the same version. The first disables an interface; the second changes its description using an old copy that still says enabled=true. An unconditional replacement can re-enable the interface and erase the first decision. When the server supplies suitable validators, retain the resource ETag and send If-Match on its corresponding write. A 412 means the condition was not satisfied: read again, reconcile the diff with authorized intent and decide again. Removing the header to make the request pass discards protection. The value * only requires a current representation to exist; it does not establish equality with the previously read version.

Errors, retries and evidence

A timeout leaves uncertainty: the client may have lost the response after the server applied the change. Read state before repeating an operation with effects. Idempotency describes the intended effect of identical requests, not the absence of logs or a guarantee of repeated status codes. For 415, inspect supported formats; when an error identifies an invalid value, review the body and model. A 403 calls for authorization analysis. More retries do not correct these causes. Follow a successful write with readback and operational checks. For an interface, enabled=true does not establish oper-status up or application transport capacity.

Lab and acceptance limits

Run the local HTTPS lab and predict outcomes before reading its evidence. Two clients read the same version; the stale write is rejected, a narrow update preserves current state, and an unconditional replacement demonstrates loss of an intervening change. The exercise also rejects a text Boolean, changed key, unsupported format and certificate with an untrusted issuer or incorrect name. Two runs passed 27 checks each. The server uses synthetic data and handwritten validation; it implements neither RESTCONF nor full YANG or NETCONF. To accept real equipment, repeat applicable checks on the exact version and model and add authorization, operational data and application traffic.

# From the project root, with Python 3 and /usr/bin/openssl available:
python3 content/labs/ccnp-api-transactions/run.py --output /tmp/ccnp-api-evidence.json
# Inspect checks and transcript in the output.
# The fixture uses loopback HTTPS and a temporary local certificate.
# It is not a Cisco device, NETCONF endpoint or conforming RESTCONF server.
IN PRACTICE

A disables uplink-7. B tries to change its description using the old version and receives 412. B reads again and sends only the authorized change, preserving enabled=false.

Common pitfalls

Partial PUT as merge; string as Boolean; 412 as credential failure; wildcard as version matching; HTTP 204 as application health.

Related topics: NETCONF and recovery · Models and data types

Take this idea with you

Protect the state you read and verify the state that remains.

Create account

Reference: RESTCONF protocol · 350-401 ENCOR v1.2, effective 2026-03-19; core component of CCNP Enterprise

CCNP® and Cisco® are registered trademarks of Cisco Systems, Inc. and/or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by Cisco. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.