kv.bind-env ​
Resolve KV keys into runtime secret_env / Pages secrets (references only)
Resolve an Orkestia KV store's keys into a runtime secret_env (Cloud Run) or a Cloudflare Pages set-secret list; grant the runtime service account accessor.
Inputs:
- connection_uuid: Bound provider CloudConnection (required)
- app: App slug (required)
- environment: Environment scope (required)
- namespace: Namespace (optional, defaults to app)
- service_account: Runtime SA to grant accessor / principal (required)
- target: cloudrun | pages (required)
- env_mapping: {key: ENV_VAR} (required)
Outputs (references only, no values):
- secret_env: {ENV_VAR: {secret, version}} — for Cloud Run
- pages_secrets: [{name, secret, version}] — for Cloudflare Pages
- bound_count
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-kv |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
connection_uuid | uuid | Yes | — | Bound provider CloudConnection. |
app | string | Yes | — | — |
environment | string | Yes | — | — |
namespace | string | No | — | Namespace (defaults to app). |
service_account | string | Yes | — | Runtime SA to grant accessor (GCP) / principal (AWS). |
target | string | Yes | — | cloudrun |
env_mapping | json | Yes | — | {key: ENV_VAR}. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
app | string | No | — | — |
environment | string | No | — | — |
namespace | string | No | — | — |
provider | string | No | — | — |
target | string | No | — | — |
secret_env | json | No | — | ENV_VAR -> {secret, version} for Cloud Run. |
pages_secrets | json | No | — | [{name, secret, version}] set-secret list for Pages. |
bound_count | integer | No | — | — |
granted | boolean | No | — | — |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "kv.bind-env",
"initial_data": {
"connection_uuid": "value",
"app": "value",
"environment": "value",
"service_account": "value"
}
}