Skip to content
Proud to collaborate with Microsoft for Startups

k8s.app.update ​

Apply a new desired state to an existing app: ConfigMap + Secret + Deployment + Service, with optional PVC / HPA / PDB / Ingress

Update a deployed app's desired state (image/env/replicas/config/secret/service).

Overview ​

PropertyValue
Workflow typeDag
LibraryApp-kubernetes
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidYes—CloudConnection UUID for the target Kubernetes cluster, picked from the organization's kubernetes-type connections.
namespacestringYes—Namespace the app lives in (must already exist)
namestringYes—App name — must match the value used at deploy time
imagestringYes—Container image reference (registry/repo:tag) — the field most updates change
portsjsonYes—List of {port, target_port?, protocol?} dicts (re-applied to Service + container)
replicasintegerNo—Replica count (default 1)
envjsonNo—NON-SECRET env vars set directly on the container. Rendered as plaintext env[].value — readable by anyone with get pod. Put credentials in secret_env, which references an existing cluster Secret instead of carrying the value.
secret_envjsonNo—Env vars sourced from EXISTING cluster Secrets: {ENV_NAME: {name: <secret>, key: <key>, optional?: bool}} or {ENV_NAME: '<secret>/<key>'}. Rendered as env[].valueFrom.secretKeyRef — the credential never enters the pod spec or workflow state.
config_datajsonNo—Key/value map mounted via envFrom.configMapRef
secret_datajsonNo—Key/value map materialised into the {name}-secrets Secret and mounted via envFrom.secretRef. Vaulted by the engine, so this DAG's own row stores a [VAULT:...] reference — but the value still reaches the kubernetes.secret.ensure child in cleartext (that primitive's data is not sensitive) and the Kafka/scheduled-transition input_data. Prefer secret_env, which references an existing Secret and never carries the value at all — see CLAUDE.md 'Secret handling'.
labelsjsonNo—Labels applied to Deployment / Service / pod template (default {app: name})
service_typestringNo—Service type (ClusterIP
timeout_secondsintegerNo—Total wait budget for rollout to become Available (default 300, cap 1800)
poll_intervalintegerNo—Seconds between status reads while waiting (default 5, cap 60)
resourcesjsonNo—Container resources {requests?, limits?} (cpu/memory)
probesjsonNo—Container probes {liveness?, readiness?, startup?} as Kubernetes probe objects
hpajsonNo—Attach an HPA named {name}: {min_replicas, max_replicas, metrics?, behavior?}. Cannot be combined with replicas — the HPA owns the replica count.
pdbjsonNo—Attach a PDB named {name}: exactly one of
volume_claimsjsonNo—PVC list [{name, size, storage_class?, access_modes?}]. Creates {app}-{name}, max 8.
volumesjsonNo—Pod volumes [{name, mount_path, claim?
ingressjsonNo—Attach an Ingress named {name}:

Output Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidNo—CloudConnection UUID for the target cluster, echoed from input.
namespacestringNo——
namestringNo——
imagestringNo——
portsjsonNo——
replicasintegerNo——
envjsonNo——
secret_envjsonNo—Secret references echoed from input — names/keys only, never values.
config_datajsonNo——
secret_datajsonNo—Echoed from input. Vaulted — this row carries a [VAULT:...] reference, not the value. Prefer secret_env.
labelsjsonNo——
service_typestringNo——
timeout_secondsintegerNo——
poll_intervalintegerNo——
resourcesjsonNo—Container resources {requests?, limits?} (cpu/memory)
probesjsonNo—Container probes {liveness?, readiness?, startup?} as Kubernetes probe objects
hpajsonNo—Attach an HPA named {name}: {min_replicas, max_replicas, metrics?, behavior?}. Cannot be combined with replicas — the HPA owns the replica count.
pdbjsonNo—Attach a PDB named {name}: exactly one of
volume_claimsjsonNo—PVC list [{name, size, storage_class?, access_modes?}]. Creates {app}-{name}, max 8.
volumesjsonNo—Pod volumes [{name, mount_path, claim?
ingressjsonNo—Attach an Ingress named {name}:
workflow_run_uuidstringNo—Engine-stamped DAG run id written by action_start.
ensure_configmapjsonNo——
ensure_secretjsonNo——
ensure_pvc_0jsonNo——
ensure_pvc_1jsonNo——
ensure_pvc_2jsonNo——
ensure_pvc_3jsonNo——
ensure_pvc_4jsonNo——
ensure_pvc_5jsonNo——
ensure_pvc_6jsonNo——
ensure_pvc_7jsonNo——
wait_pvc_0jsonNo——
wait_pvc_1jsonNo——
wait_pvc_2jsonNo——
wait_pvc_3jsonNo——
wait_pvc_4jsonNo——
wait_pvc_5jsonNo——
wait_pvc_6jsonNo——
wait_pvc_7jsonNo——
ensure_deploymentjsonNo——
ensure_servicejsonNo——
ensure_hpajsonNo——
ensure_pdbjsonNo——
ensure_ingressjsonNo——
wait_for_rolloutjsonNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

DAG Layers ​

#LayerStepsCompensation
1configkubernetes.configmap.ensure, kubernetes.secret.ensure, kubernetes.pvc.ensure, kubernetes.pvc.ensure, kubernetes.pvc.ensure, kubernetes.pvc.ensure, kubernetes.pvc.ensure, kubernetes.pvc.ensure, kubernetes.pvc.ensure, kubernetes.pvc.ensure—
2wait_storagekubernetes.pvc.wait_for_bound, kubernetes.pvc.wait_for_bound, kubernetes.pvc.wait_for_bound, kubernetes.pvc.wait_for_bound, kubernetes.pvc.wait_for_bound, kubernetes.pvc.wait_for_bound, kubernetes.pvc.wait_for_bound, kubernetes.pvc.wait_for_bound—
3workloadkubernetes.deployment.ensure, kubernetes.service.ensure—
4policykubernetes.horizontalpodautoscaler.ensure, kubernetes.poddisruptionbudget.ensure, kubernetes.ingress.ensure—
5waitkubernetes.deployment.wait_for_available—

Execution Flow ​

Sub-workflows ​

Sub-workflowStep name
kubernetes.configmap.ensureensure_configmap
kubernetes.secret.ensureensure_secret
kubernetes.pvc.ensureensure_pvc_0
kubernetes.pvc.wait_for_boundwait_pvc_0
kubernetes.deployment.ensureensure_deployment
kubernetes.service.ensureensure_service
kubernetes.horizontalpodautoscaler.ensureensure_hpa
kubernetes.poddisruptionbudget.ensureensure_pdb
kubernetes.ingress.ensureensure_ingress
kubernetes.deployment.wait_for_availablewait_for_rollout

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "k8s.app.update",
  "initial_data": {
    "connection_uuid": "value",
    "namespace": "value",
    "name": "value",
    "image": "value"
  }
}