network.azure.runner-segment.ensure
Ensure a VNet, subnet, and NSG on a customer Azure connection for runner VMs. Default egress is a per-VM public IP (cheapest); egress_mode=nat_gateway provisions a shared NAT Gateway instead.
Ensure a tagged Azure runner VNet/subnet and optional NAT or public-IP egress.
Overview
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-network |
| Version | 1.0 |
Input Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | — |
connection_uuid | uuid | Yes | — | — |
resource_group | string | Yes | — | — |
location | string | Yes | — | — |
vnet_name | string | No | — | — |
vnet_cidr | string | No | — | — |
subnet_name | string | No | — | — |
subnet_cidr | string | No | — | — |
nsg_name | string | No | — | — |
egress_mode | string | No | — | public_ip (default, cheapest) or nat_gateway |
runner_group_uuid | uuid | No | — | — |
network_account_name | string | No | — | — |
Output Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | No | — | — |
connection_uuid | uuid | No | — | — |
resource_group | string | No | — | — |
location | string | No | — | — |
vnet_ref | string | No | — | ARM id of the ensured virtual network |
subnet_ref | string | No | — | ARM id of the ensured subnet |
nsg_ref | string | No | — | ARM id of the ensured NSG |
nat_gateway_ref | string | No | — | ARM id of the NAT Gateway when egress_mode=nat_gateway |
network_account_uuid | uuid | No | — | — |
egress_mode | string | No | — | — |
persist_account | json | No | — | — |
ensure_vnet | json | No | — | — |
ensure_nsg | json | No | — | — |
ensure_nat_pip | json | No | — | — |
ensure_nat_gateway | json | No | — | — |
ensure_subnet | json | No | — | — |
sync_account | json | No | — | — |
bind_runner_group | json | No | — | — |
failure_reason | string | No | — | Engine-stamped human-readable failure reason |
failed_at_state | string | No | — | Engine-stamped state when the workflow failed |
failed_step | string | No | — | Engine-stamped step name (DAG path) |
failed_layer | integer | No | — | Engine-stamped layer index (DAG path) |
error | string | No | — | Engine-stamped exception message |
error_type | string | No | — | Engine-stamped exception class name |
DAG Layers
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | account | data.network.account.persist | — |
| 2 | vnet | azure.network.vnet.ensure | — |
| 3 | nsg | azure.network.nsg.ensure | — |
| 4 | nat_pip | azure.network.publicip.ensure | — |
| 5 | nat_gateway | azure.network.natgateway.ensure | — |
| 6 | subnet | azure.network.subnet.ensure | — |
| 7 | sync | network.account-sync | — |
| 8 | bind | data.runner.group-update | — |
Execution Flow
Sub-workflows
| Sub-workflow | Step name |
|---|---|
data.network.account.persist | persist_account |
azure.network.vnet.ensure | ensure_vnet |
azure.network.nsg.ensure | ensure_nsg |
azure.network.publicip.ensure | ensure_nat_pip |
azure.network.natgateway.ensure | ensure_nat_gateway |
azure.network.subnet.ensure | ensure_subnet |
network.account-sync | sync_account |
data.runner.group-update | bind_runner_group |
Outcomes
| Outcome | Type | Description | State Data Keys |
|---|---|---|---|
ensured | SUCCESS | Ensure a VNet, subnet, and NSG on a customer Azure connection for runner VMs. Default egress is a per-VM public IP (cheapest); egress_mode=nat_gateway provisions a shared NAT Gateway instead. | — |
failed | FAILURE | Network workflow failed | failure_reason |
API Usage
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "network.azure.runner-segment.ensure",
"initial_data": {
"organization_uuid": "value",
"connection_uuid": "value",
"resource_group": "value",
"location": "value"
}
}