cluster.bootstrap-orkestia-access ​
Ensure standard namespace, service account, RBAC binding, and optional manifests for Orkestia access.
Ensure standard namespace, service account, RBAC, and optional manifests.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Linear |
| Library | App-clusters |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Organization UUID for tenant isolation and audit. |
connection_uuid | uuid | Yes | — | Kubernetes CloudConnection UUID. |
namespace | string | No | — | Namespace to ensure; defaults to orkestia. |
namespace_labels | json | No | — | Labels for the namespace. |
service_account_name | string | No | — | ServiceAccount name; defaults to orkestia. |
image_pull_secrets | json | No | — | Optional image pull secret refs for the ServiceAccount. |
automount_service_account_token | boolean | No | — | ServiceAccount automount flag. |
service_account_labels | json | No | — | Labels for the ServiceAccount. |
cluster_role_binding_name | string | No | — | ClusterRoleBinding name; defaults to orkestia-access. |
role_ref | json | No | — | Kubernetes roleRef; defaults to the built-in view ClusterRole. |
allow_cluster_admin | boolean | No | — | Required when role_ref binds the cluster-admin ClusterRole. |
subjects | json | No | — | ClusterRoleBinding subjects; defaults to the ensured ServiceAccount. |
manifests | json | No | — | Optional extra manifests to apply after RBAC. |
actor | string | No | — | Caller initiating bootstrap. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
ensure_namespace | json | No | — | Output from kubernetes.namespace.ensure. |
ensure_service_account | json | No | — | Output from kubernetes.serviceaccount.ensure. |
ensure_cluster_role_binding | json | No | — | Output from kubernetes.clusterrolebinding.ensure. |
apply_manifests | json | No | — | Outputs from kubernetes.manifest.apply fanout. |
organization_uuid | uuid | No | — | Organization UUID echoed from input. |
connection_uuid | uuid | No | — | Kubernetes CloudConnection UUID. |
namespace | string | No | — | Ensured namespace. |
service_account_name | string | No | — | Ensured ServiceAccount. |
cluster_role_binding_name | string | No | — | Ensured ClusterRoleBinding. |
applied_manifest_count | integer | No | — | Number of extra manifests applied. |
bootstrapped | boolean | No | — | True when required resources were ensured. |
bootstrapped_at | string | No | — | ISO bootstrap timestamp. |
failure_reason | string | No | — | Human-readable failure reason. |
failure_type | string | No | — | Failure category. |
failed_action | string | No | — | Action that failed. |
failed_step | json | No | — | Failed logical step or child workflow. |
failed_layer | json | No | — | Engine failed layer when applicable. |
failed_at_state | string | No | — | State where failure occurred. |
error | string | No | — | Error message. |
error_type | string | No | — | Error class. |
failed_at | string | No | — | ISO failure timestamp. |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | bootstrap | — |
bootstrapping | No | No | — | complete | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | bootstrap | bootstrapping | — |
bootstrapping | complete | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "cluster.bootstrap-orkestia-access",
"initial_data": {
"organization_uuid": "value",
"connection_uuid": "value"
}
}