apphost.addon.object.sign-get
Mint a short-lived GET URL for an attachment on this site's MinIO PVC. Requires an end-user principal and a visible conversation row. Not data.appdata.document.*.
Overview
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-apphost |
| Version | 1.0 |
Input Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
site_uuid | uuid | Yes | — | — |
conversation_uuid | uuid | Yes | — | — |
name | string | Yes | — | — |
database_slug | string | No | — | — |
conversation_table | string | No | — | — |
addon | string | No | buzz | — |
ttl_seconds | integer | No | — | — |
Output Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
site_uuid | uuid | No | — | — |
conversation_uuid | uuid | No | — | — |
name | string | No | — | — |
database_slug | string | No | — | — |
conversation_table | string | No | — | — |
addon | string | No | — | — |
ttl_seconds | integer | No | — | — |
resolve | json | No | — | — |
authorize | json | No | — | — |
member | json | No | — | — |
secrets_key | json | No | — | — |
secrets_material | json | No | — | — |
signed | json | No | — | — |
ack | json | No | — | — |
failure_reason | string | No | — | Engine-stamped failure reason |
failure_type | string | No | — | Stable failure classification |
failed_action | string | No | — | Action that failed |
failed_at_state | string | No | — | State when the workflow failed |
failed_step | json | No | — | Failed DAG step envelope |
failed_layer | json | No | — | Failed DAG layer envelope |
error | string | No | — | Engine-stamped exception message |
error_type | string | No | — | Engine-stamped exception class name |
compensation_trigger | json | No | — | — |
comp_queue | json | No | — | — |
comp_current_layer | json | No | — | — |
comp_retry_count | json | No | — | — |
DAG Layers
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | resolve | apphost.addon.resolve | apphost.web.ack |
| 2 | authorize | apphost.addon.object.authorize | apphost.web.ack |
| 3 | member | data.appdata.record.read | apphost.web.ack |
| 4 | secrets_key | identity.key.query | apphost.web.ack |
| 5 | secrets_material | identity.key.materialize | apphost.web.ack |
| 6 | sign | apphost.addon.object.sign-get-execute | — |
Execution Flow
Compensation
When any layer fails, its compensation steps run in reverse order to roll back the work completed so far.
Sub-workflows
| Sub-workflow | Step name |
|---|---|
apphost.addon.resolve | resolve |
apphost.addon.object.authorize | authorize |
data.appdata.record.read | member |
identity.key.query | secrets_key |
identity.key.materialize | secrets_material |
apphost.addon.object.sign-get-execute | signed |
apphost.web.ack | ack |
Outcomes
| Outcome | Type | Description | State Data Keys |
|---|---|---|---|
signed | SUCCESS | Signed GET URL minted | url |
failed | FAILURE | Apphost workflow failed | failure_reason |
API Usage
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "apphost.addon.object.sign-get",
"initial_data": {
"site_uuid": "value",
"conversation_uuid": "value",
"name": "value"
}
}