Skip to content
Proud to collaborate with Microsoft for Startups

k8s.manifest.diff_set ​

Drift report for a desired manifest set (no mutation)

Compute a drift report for a desired manifest set without mutating the cluster.

For each manifest, GETs the live object and server-side-apply dry-runs it, diffing top-level fields (excluding metadata/status). Returns the subset that is out of sync.

Inputs:

  • connection_uuid: CloudConnection UUID for the target cluster (required).
  • manifests: List of resource manifest dicts (required).
  • namespace: Default namespace for namespaced manifests (optional).

Outputs:

  • out_of_sync: [{api_version, kind, namespace, name, status, changed_fields, live, desired}] status = "missing" (would create) | "drift" (would update). live/desired are the sanitized current and projected (dry-run server-side-apply) objects, so callers can render a full field-level / YAML diff. live is null for "missing". Secret payloads are projected to key names — every value is replaced with "[REDACTED]" so the report, which is persisted to unencrypted state_data, never carries credentials. Drift itself is computed on the raw objects, so changed_fields still reports a Secret whose data differs.
  • in_sync_count: int — manifests already matching the cluster.
  • is_synced: bool — True when out_of_sync is empty.

Plugin required: context.get_plugin("connection").kubernetes_runner_clients(connection_uuid, organization_uuid) exposing api_client.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-kubernetes
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidYes—CloudConnection UUID for the target cluster
manifestsjsonYes—List of resource manifest dicts
namespacestringNo—Default namespace for namespaced manifests

Output Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidNo—CloudConnection UUID echoed from input.
manifestsjsonNo——
namespacestringNo——
out_of_syncjsonNo—Drift entries. live/desired are sanitized; Secret payload values are redacted to key names.
in_sync_countintegerNo——
is_syncedbooleanNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "k8s.manifest.diff_set",
  "initial_data": {
    "connection_uuid": "value",
    "manifests": "value"
  }
}