Skip to content
Proud to collaborate with Microsoft for Startups

kv.bind-env ​

Resolve KV keys into runtime secret_env / Pages secrets (references only)

Resolve an Orkestia KV store's keys into a runtime secret_env (Cloud Run) or a Cloudflare Pages set-secret list; grant the runtime service account accessor.

Inputs:

  • connection_uuid: Bound provider CloudConnection (required)
  • app: App slug (required)
  • environment: Environment scope (required)
  • namespace: Namespace (optional, defaults to app)
  • service_account: Runtime SA to grant accessor / principal (required)
  • target: cloudrun | pages (required)
  • env_mapping: {key: ENV_VAR} (required)

Outputs (references only, no values):

  • secret_env: {ENV_VAR: {secret, version}} — for Cloud Run
  • pages_secrets: [{name, secret, version}] — for Cloudflare Pages
  • bound_count

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-kv
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidYes—Bound provider CloudConnection.
appstringYes——
environmentstringYes——
namespacestringNo—Namespace (defaults to app).
service_accountstringYes—Runtime SA to grant accessor (GCP) / principal (AWS).
targetstringYes—cloudrun
env_mappingjsonYes—{key: ENV_VAR}.

Output Schema ​

FieldTypeRequiredDefaultDescription
appstringNo——
environmentstringNo——
namespacestringNo——
providerstringNo——
targetstringNo——
secret_envjsonNo—ENV_VAR -> {secret, version} for Cloud Run.
pages_secretsjsonNo—[{name, secret, version}] set-secret list for Pages.
bound_countintegerNo——
grantedbooleanNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "kv.bind-env",
  "initial_data": {
    "connection_uuid": "value",
    "app": "value",
    "environment": "value",
    "service_account": "value"
  }
}