Skip to content
Proud to collaborate with Microsoft for Startups

deploy.service.bind-secrets ​

Materialize runtime secrets in GCP Secret Manager and grant service-account access.

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-deployments
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
workflow_run_idstringNo—Engine-stamped DAG step run ID.
organization_uuiduuidYes—Organization UUID.
connection_uuiduuidYes—GCP connection UUID.
project_idstringNo—GCP project override.
service_namestringYes—Logical service name.
service_accountstringYes—Runtime service account email.
secretslistYes—Secret requirements; values are sensitive and optional for existing secrets.
labelsjsonNo—Labels applied to generated secrets.

Output Schema ​

FieldTypeRequiredDefaultDescription
workflow_run_idstringNo—Engine-stamped DAG step run ID.
organization_uuiduuidNo—Echoed organization UUID.
connection_uuiduuidNo—Echoed GCP connection UUID.
project_idstringNo—Effective project.
service_namestringNo—Logical service name.
service_accountstringNo—Runtime service account.
secret_envjsonNo—Env var to Secret Manager version references for Cloud Run.
secret_countintegerNo—Secrets processed.
rotated_countintegerNo—Secret versions created.
granted_countintegerNo—Secret IAM grants applied.
failure_reasonstringNo—Engine failure reason.
failed_stepjsonNo—Failed DAG step envelope.
failed_layerjsonNo—Failed DAG layer envelope.
failed_at_statestringNo—State where failure occurred.
errorstringNo—Error message.
error_typestringNo—Error class.

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—bind—
bindingNoNo—complete—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingbindbinding—
bindingcompletecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "deploy.service.bind-secrets",
  "initial_data": {
    "organization_uuid": "value",
    "connection_uuid": "value",
    "service_name": "value",
    "service_account": "value"
  }
}