appdata.instance.ensure-system-tables ​
Ensure an app's own instance carries the appdata audit trail and replay ledger; idempotent, and a no-op for apps on the shared plane
Give an already-provisioned instance the audit trail and replay ledger.
They arrived with virtual-engine 0.8.0, so every app provisioned before it has an instance without them, and nothing adds them retroactively: structure.apply emits them but requires the owning org to re-apply a declaration, and instance.migrate must never be re-run on an app that already migrated (it restores data on top of live rows).
Idempotent by construction -- every statement is CREATE ... IF NOT EXISTS, DROP/CREATE POLICY, GRANT or REVOKE -- so it can be run across every app without first working out which ones need it, and re-run without harm.
It touches no customer table, view or trigger. That is the reason it exists as its own entry point rather than as a structure re-apply, which would drag column evolution and policy replacement into a change nobody asked for.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-appdata |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Authenticated organization UUID |
identity_app_uuid | uuid | Yes | — | Identity app the credential reads; must own an appdata namespace in this organization |
request_id | string | No | — | Caller request id for audit correlation |
actor | string | No | — | — |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | — |
identity_app_uuid | uuid | Yes | — | — |
backend_kind | string | Yes | — | shared |
statements_applied | integer | No | — | DDL statements executed on the instance |
system_tables | list | No | — | The per-instance tables this guarantees exist |
failure_reason | string | No | — | Engine-stamped failure reason |
failed_at_state | string | No | — | State when the workflow failed |
failed_step | string | No | — | Failed DAG step name |
failed_layer | integer | No | — | Failed DAG layer index |
error | string | No | — | Engine-stamped exception message |
error_type | string | No | — | Engine-stamped exception class name |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | complete | Ensure credential |
completed | No | Yes | Yes | — | Credential ensured |
failed | No | Yes | No | — | Ensure failed |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | complete | completed | — |
pending | fail | failed | — |
Outcomes ​
| Outcome | Type | Description | State Data Keys |
|---|---|---|---|
ensured | SUCCESS | Ensure an app's own instance carries the appdata audit trail and replay ledger; idempotent, and a no-op for apps on the shared plane | backend_kind, statements_applied |
failed | FAILURE | Appdata workflow failed | failure_reason |
API Usage ​
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "appdata.instance.ensure-system-tables",
"initial_data": {
"organization_uuid": "value",
"identity_app_uuid": "value"
}
}