Skip to content
Proud to collaborate with Microsoft for Startups

appdata.instance.ensure-system-tables ​

Ensure an app's own instance carries the appdata audit trail and replay ledger; idempotent, and a no-op for apps on the shared plane

Give an already-provisioned instance the audit trail and replay ledger.

They arrived with virtual-engine 0.8.0, so every app provisioned before it has an instance without them, and nothing adds them retroactively: structure.apply emits them but requires the owning org to re-apply a declaration, and instance.migrate must never be re-run on an app that already migrated (it restores data on top of live rows).

Idempotent by construction -- every statement is CREATE ... IF NOT EXISTS, DROP/CREATE POLICY, GRANT or REVOKE -- so it can be run across every app without first working out which ones need it, and re-run without harm.

It touches no customer table, view or trigger. That is the reason it exists as its own entry point rather than as a structure re-apply, which would drag column evolution and policy replacement into a change nobody asked for.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-appdata
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Authenticated organization UUID
identity_app_uuiduuidYes—Identity app the credential reads; must own an appdata namespace in this organization
request_idstringNo—Caller request id for audit correlation
actorstringNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes——
identity_app_uuiduuidYes——
backend_kindstringYes—shared
statements_appliedintegerNo—DDL statements executed on the instance
system_tableslistNo—The per-instance tables this guarantees exist
failure_reasonstringNo—Engine-stamped failure reason
failed_at_statestringNo—State when the workflow failed
failed_stepstringNo—Failed DAG step name
failed_layerintegerNo—Failed DAG layer index
errorstringNo—Engine-stamped exception message
error_typestringNo—Engine-stamped exception class name

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—completeEnsure credential
completedNoYesYes—Credential ensured
failedNoYesNo—Ensure failed

State Diagram ​

Transitions ​

FromActionToDescription
pendingcompletecompleted—
pendingfailfailed—

Outcomes ​

OutcomeTypeDescriptionState Data Keys
ensuredSUCCESSEnsure an app's own instance carries the appdata audit trail and replay ledger; idempotent, and a no-op for apps on the shared planebackend_kind, statements_applied
failedFAILUREAppdata workflow failedfailure_reason

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "appdata.instance.ensure-system-tables",
  "initial_data": {
    "organization_uuid": "value",
    "identity_app_uuid": "value"
  }
}