Skip to content
Proud to collaborate with Microsoft for Startups

Kubernetes ​

WorkflowTypeDescription
kubernetes.cluster.api_resourcesAtomicList all API resources advertised by the cluster (kubectl api-resources equivalent)
kubernetes.cluster.versionAtomicRead Kubernetes API server version.
kubernetes.clusterrole.deleteAtomicDelete a ClusterRole (cluster-scoped, rbac.authorization.k8s.io/v1)
kubernetes.clusterrole.ensureAtomicCreate or replace a ClusterRole (cluster-scoped, rbac.authorization.k8s.io/v1)
kubernetes.clusterrole.listAtomicEnumerate ClusterRoles (cluster-scoped)
kubernetes.clusterrolebinding.deleteAtomicDelete a ClusterRoleBinding (cluster-scoped, rbac.authorization.k8s.io/v1)
kubernetes.clusterrolebinding.ensureAtomicCreate or replace a ClusterRoleBinding (cluster-scoped). role_ref is immutable; existing binding with different role_ref is deleted and recreated.
kubernetes.clusterrolebinding.listAtomicEnumerate ClusterRoleBindings (cluster-scoped)
kubernetes.configmap.deleteAtomicDelete a namespaced Kubernetes ConfigMap
kubernetes.configmap.ensureAtomicCreate or replace a namespaced Kubernetes ConfigMap
kubernetes.configmap.getAtomicRead a single ConfigMap (data and binary_data included)
kubernetes.configmap.listAtomicList ConfigMaps in a namespace
kubernetes.connection.identityAtomicRead effective Kubernetes user identity.
kubernetes.cronjob.deleteAtomicDelete a namespaced Kubernetes CronJob
kubernetes.cronjob.ensureAtomicCreate or replace a namespaced Kubernetes CronJob (batch/v1)
kubernetes.cronjob.listAtomicEnumerate CronJobs in a namespace (batch/v1)
kubernetes.daemonset.deleteAtomicDelete a namespaced Kubernetes DaemonSet
kubernetes.daemonset.ensureAtomicCreate or replace a namespaced Kubernetes DaemonSet
kubernetes.daemonset.listAtomicEnumerate DaemonSets in a namespace
kubernetes.deployment.deleteAtomicDelete a namespaced Kubernetes Deployment
kubernetes.deployment.ensureAtomicCreate or replace a namespaced Kubernetes Deployment
kubernetes.deployment.getAtomicRead a single Deployment's metadata, spec, and status
kubernetes.deployment.listAtomicEnumerate Deployments in a namespace
kubernetes.deployment.patchAtomicApply a strategic-merge, JSON-merge, or JSON patch to a Deployment
kubernetes.deployment.pauseAtomicPause a Deployment rollout (kubectl rollout pause equivalent)
kubernetes.deployment.restartAtomicTrigger a rollout restart of a Deployment (kubectl rollout restart equivalent)
kubernetes.deployment.resumeAtomicResume a paused Deployment rollout (kubectl rollout resume equivalent)
kubernetes.deployment.rollbackAtomicRoll a Deployment back to a previous revision (kubectl rollout undo equivalent)
kubernetes.deployment.rollout_statusAtomicReport current rollout state of a Deployment (single read; not a watcher)
kubernetes.deployment.scaleAtomicSet the replica count on a Deployment (scale subresource)
kubernetes.deployment.set_imageAtomicUpdate a Deployment container's image (kubectl set image equivalent) — triggers a rolling update
kubernetes.deployment.wait_for_availableAtomicPoll a Kubernetes Deployment until rollout completes or timeout
kubernetes.event.listAtomicList events in a namespace, newest first
kubernetes.horizontalpodautoscaler.deleteAtomicDelete a namespaced Kubernetes HorizontalPodAutoscaler
kubernetes.horizontalpodautoscaler.ensureAtomicCreate or replace a namespaced Kubernetes HorizontalPodAutoscaler (autoscaling/v2)
kubernetes.horizontalpodautoscaler.listAtomicEnumerate HorizontalPodAutoscalers with their live scaling state
kubernetes.ingress.deleteAtomicDelete a namespaced Kubernetes Ingress
kubernetes.ingress.ensureAtomicCreate or replace a namespaced Kubernetes Ingress (networking.k8s.io/v1)
kubernetes.ingress.listAtomicEnumerate Ingresses in a namespace (networking.k8s.io/v1)
kubernetes.job.deleteAtomicDelete a Kubernetes Job
kubernetes.job.ensureAtomicCreate a Kubernetes Job; pass replace=true to delete+recreate if it already exists (Jobs are immutable)
kubernetes.job.listAtomicEnumerate Jobs in a namespace
kubernetes.job.wait_for_completeLinearPoll a Kubernetes Job until it reaches Complete or Failed condition (or timeout)
kubernetes.limitrange.deleteAtomicDelete a namespaced Kubernetes LimitRange
kubernetes.limitrange.ensureAtomicCreate or replace a namespaced Kubernetes LimitRange
kubernetes.limitrange.listAtomicEnumerate LimitRanges in a namespace
kubernetes.manifest.applyAtomicCreate or replace any Kubernetes resource from a raw manifest dict
kubernetes.manifest.apply_ssaAtomicServer-side apply (SSA) a single Kubernetes manifest
kubernetes.manifest.deleteAtomicDelete any Kubernetes resource by (apiVersion, kind, name, namespace)
kubernetes.manifest.diffAtomicServer-side dry-run a manifest to preview what would change (no mutation)
kubernetes.manifest.validateAtomicServer-side schema validation of a manifest with strict field checking (no mutation)
kubernetes.namespace.deleteAtomicDelete a Kubernetes Namespace
kubernetes.namespace.ensureAtomicCreate a Kubernetes Namespace if it does not exist
kubernetes.namespace.listAtomicEnumerate namespaces on a Kubernetes cluster
kubernetes.networkpolicy.deleteAtomicDelete a namespaced Kubernetes NetworkPolicy
kubernetes.networkpolicy.ensureAtomicCreate or replace a namespaced Kubernetes NetworkPolicy (networking.k8s.io/v1)
kubernetes.networkpolicy.getAtomicRead a single NetworkPolicy (full spec included)
kubernetes.networkpolicy.listAtomicEnumerate NetworkPolicies in a namespace (networking.k8s.io/v1)
kubernetes.networkpolicy.verify-receiptAtomicIndependent read-only receipt of NetworkPolicies applied in one or more namespaces (canonical spec digest)
kubernetes.node.cordonAtomicMark a Node as unschedulable (kubectl cordon equivalent)
kubernetes.node.drainLinearCordon a Node and evict its Pods (kubectl drain equivalent)
kubernetes.node.listAtomicEnumerate all Nodes in a Kubernetes cluster
kubernetes.node.uncordonAtomicMark a Node as schedulable (kubectl uncordon equivalent)
kubernetes.persistentvolume.deleteAtomicDelete a cluster PersistentVolume (destructive; reclaims orphaned storage)
kubernetes.persistentvolume.listAtomicEnumerate cluster PersistentVolumes, flagging orphaned storage
kubernetes.pod.deleteAtomicDelete a Pod (controller-managed pods will be recreated by their controller)
kubernetes.pod.execLinearRun a command on a Pod over a long-lived WebSocket session
kubernetes.pod.getAtomicRead a single Pod's metadata, spec, and status
kubernetes.pod.listAtomicEnumerate Pods in a namespace
kubernetes.pod.logsAtomicRead recent logs from a Pod (one-shot tail; not streaming)
kubernetes.pod.logs_streamLinearFollow a Pod's logs over a long-lived WebSocket session
kubernetes.pod.port_forwardLinearForward a local WebSocket to a TCP port on a Pod
kubernetes.poddisruptionbudget.deleteAtomicDelete a namespaced Kubernetes PodDisruptionBudget
kubernetes.poddisruptionbudget.ensureAtomicCreate or replace a namespaced Kubernetes PodDisruptionBudget (policy/v1)
kubernetes.poddisruptionbudget.listAtomicEnumerate PodDisruptionBudgets, flagging any that block a drain
kubernetes.pvc.deleteAtomicDelete a namespaced Kubernetes PersistentVolumeClaim (note: underlying PV may be retained or deleted based on reclaim policy)
kubernetes.pvc.ensureAtomicCreate or replace a namespaced Kubernetes PersistentVolumeClaim
kubernetes.pvc.listAtomicEnumerate PersistentVolumeClaims in a namespace
kubernetes.pvc.wait_for_boundLinearPoll a PersistentVolumeClaim until status.phase == Bound, or timeout
kubernetes.rbac.can_iAtomicCheck whether the connection's identity can perform a verb on a resource (kubectl auth can-i equivalent)
kubernetes.resource.wait_for_conditionLinearGeneric kubectl-wait equivalent: poll any Kubernetes resource until a condition matches the requested status
kubernetes.resourcequota.deleteAtomicDelete a namespaced Kubernetes ResourceQuota
kubernetes.resourcequota.ensureAtomicCreate or replace a namespaced Kubernetes ResourceQuota
kubernetes.resourcequota.getAtomicRead a ResourceQuota with its live consumption and utilization
kubernetes.resourcequota.listAtomicEnumerate ResourceQuotas in a namespace with their utilization
kubernetes.role.deleteAtomicDelete a namespaced Kubernetes Role (rbac.authorization.k8s.io/v1)
kubernetes.role.ensureAtomicCreate or replace a namespaced Kubernetes Role (rbac.authorization.k8s.io/v1)
kubernetes.role.listAtomicEnumerate Roles in a namespace
kubernetes.rolebinding.deleteAtomicDelete a namespaced Kubernetes RoleBinding (rbac.authorization.k8s.io/v1)
kubernetes.rolebinding.ensureAtomicCreate or replace a namespaced Kubernetes RoleBinding (role_ref is immutable; existing binding with different role_ref is deleted and recreated)
kubernetes.rolebinding.listAtomicEnumerate RoleBindings in a namespace
kubernetes.secret.deleteAtomicDelete a namespaced Kubernetes Secret
kubernetes.secret.ensureAtomicCreate or replace a namespaced Kubernetes Secret
kubernetes.secret.getAtomicRead a single Secret (data values redacted by default; pass reveal=true to include them)
kubernetes.secret.listAtomicList Secrets in a namespace (keys + metadata only — values are not returned)
kubernetes.service.deleteAtomicDelete a namespaced Kubernetes Service
kubernetes.service.ensureAtomicCreate or replace a namespaced Kubernetes Service
kubernetes.service.getAtomicRead a single Service's spec and status
kubernetes.service.listAtomicList Services in a namespace
kubernetes.serviceaccount.deleteAtomicDelete a namespaced Kubernetes ServiceAccount
kubernetes.serviceaccount.ensureAtomicCreate or replace a namespaced Kubernetes ServiceAccount
kubernetes.serviceaccount.listAtomicEnumerate ServiceAccounts in a namespace
kubernetes.statefulset.deleteAtomicDelete a namespaced Kubernetes StatefulSet
kubernetes.statefulset.ensureAtomicCreate or replace a namespaced Kubernetes StatefulSet
kubernetes.statefulset.listAtomicEnumerate StatefulSets in a namespace
kubernetes.statefulset.wait_for_readyLinearPoll a StatefulSet until all replicas are ready or timeout
kubernetes.storageclass.listAtomicEnumerate the cluster's StorageClasses and identify the default
kubernetes.target_availability.verifyAtomicProve deny-test targets are present and available before treating access-denied as evidence
kubernetes.workload.healthcheckAtomicAtomic adapter for kubernetes.workload.healthcheck; required by parent workflow specs: kubernetes.app.deploy-from-image, kubernetes.workload.rollback-after-healthcheck.