Skip to content
Proud to collaborate with Microsoft for Startups

cluster.bootstrap-orkestia-access ​

Ensure standard namespace, service account, RBAC binding, and optional manifests for Orkestia access.

Ensure standard namespace, service account, RBAC, and optional manifests.

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-clusters
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Organization UUID for tenant isolation and audit.
connection_uuiduuidYes—Kubernetes CloudConnection UUID.
namespacestringNo—Namespace to ensure; defaults to orkestia.
namespace_labelsjsonNo—Labels for the namespace.
service_account_namestringNo—ServiceAccount name; defaults to orkestia.
image_pull_secretsjsonNo—Optional image pull secret refs for the ServiceAccount.
automount_service_account_tokenbooleanNo—ServiceAccount automount flag.
service_account_labelsjsonNo—Labels for the ServiceAccount.
cluster_role_binding_namestringNo—ClusterRoleBinding name; defaults to orkestia-access.
role_refjsonNo—Kubernetes roleRef; defaults to the built-in view ClusterRole.
allow_cluster_adminbooleanNo—Required when role_ref binds the cluster-admin ClusterRole.
subjectsjsonNo—ClusterRoleBinding subjects; defaults to the ensured ServiceAccount.
manifestsjsonNo—Optional extra manifests to apply after RBAC.
actorstringNo—Caller initiating bootstrap.

Output Schema ​

FieldTypeRequiredDefaultDescription
ensure_namespacejsonNo—Output from kubernetes.namespace.ensure.
ensure_service_accountjsonNo—Output from kubernetes.serviceaccount.ensure.
ensure_cluster_role_bindingjsonNo—Output from kubernetes.clusterrolebinding.ensure.
apply_manifestsjsonNo—Outputs from kubernetes.manifest.apply fanout.
organization_uuiduuidNo—Organization UUID echoed from input.
connection_uuiduuidNo—Kubernetes CloudConnection UUID.
namespacestringNo—Ensured namespace.
service_account_namestringNo—Ensured ServiceAccount.
cluster_role_binding_namestringNo—Ensured ClusterRoleBinding.
applied_manifest_countintegerNo—Number of extra manifests applied.
bootstrappedbooleanNo—True when required resources were ensured.
bootstrapped_atstringNo—ISO bootstrap timestamp.
failure_reasonstringNo—Human-readable failure reason.
failure_typestringNo—Failure category.
failed_actionstringNo—Action that failed.
failed_stepjsonNo—Failed logical step or child workflow.
failed_layerjsonNo—Engine failed layer when applicable.
failed_at_statestringNo—State where failure occurred.
errorstringNo—Error message.
error_typestringNo—Error class.
failed_atstringNo—ISO failure timestamp.

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—bootstrap—
bootstrappingNoNo—complete—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingbootstrapbootstrapping—
bootstrappingcompletecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "cluster.bootstrap-orkestia-access",
  "initial_data": {
    "organization_uuid": "value",
    "connection_uuid": "value"
  }
}