Skip to content
Proud to collaborate with Microsoft for Startups

network.azure.runner-segment.ensure ​

Ensure a VNet, subnet, and NSG on a customer Azure connection for runner VMs. Default egress is a per-VM public IP (cheapest); egress_mode=nat_gateway provisions a shared NAT Gateway instead.

Ensure a tagged Azure runner VNet/subnet and optional NAT or public-IP egress.

Overview ​

PropertyValue
Workflow typeDag
LibraryApp-network
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes——
connection_uuiduuidYes——
resource_groupstringYes——
locationstringYes——
vnet_namestringNo——
vnet_cidrstringNo——
subnet_namestringNo——
subnet_cidrstringNo——
nsg_namestringNo——
egress_modestringNo—public_ip (default, cheapest) or nat_gateway
runner_group_uuiduuidNo——
network_account_namestringNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidNo——
connection_uuiduuidNo——
resource_groupstringNo——
locationstringNo——
vnet_refstringNo—ARM id of the ensured virtual network
subnet_refstringNo—ARM id of the ensured subnet
nsg_refstringNo—ARM id of the ensured NSG
nat_gateway_refstringNo—ARM id of the NAT Gateway when egress_mode=nat_gateway
network_account_uuiduuidNo——
egress_modestringNo——
persist_accountjsonNo——
ensure_vnetjsonNo——
ensure_nsgjsonNo——
ensure_nat_pipjsonNo——
ensure_nat_gatewayjsonNo——
ensure_subnetjsonNo——
sync_accountjsonNo——
bind_runner_groupjsonNo——
failure_reasonstringNo—Engine-stamped human-readable failure reason
failed_at_statestringNo—Engine-stamped state when the workflow failed
failed_stepstringNo—Engine-stamped step name (DAG path)
failed_layerintegerNo—Engine-stamped layer index (DAG path)
errorstringNo—Engine-stamped exception message
error_typestringNo—Engine-stamped exception class name

DAG Layers ​

#LayerStepsCompensation
1accountdata.network.account.persist—
2vnetazure.network.vnet.ensure—
3nsgazure.network.nsg.ensure—
4nat_pipazure.network.publicip.ensure—
5nat_gatewayazure.network.natgateway.ensure—
6subnetazure.network.subnet.ensure—
7syncnetwork.account-sync—
8binddata.runner.group-update—

Execution Flow ​

Sub-workflows ​

Sub-workflowStep name
data.network.account.persistpersist_account
azure.network.vnet.ensureensure_vnet
azure.network.nsg.ensureensure_nsg
azure.network.publicip.ensureensure_nat_pip
azure.network.natgateway.ensureensure_nat_gateway
azure.network.subnet.ensureensure_subnet
network.account-syncsync_account
data.runner.group-updatebind_runner_group

Outcomes ​

OutcomeTypeDescriptionState Data Keys
ensuredSUCCESSEnsure a VNet, subnet, and NSG on a customer Azure connection for runner VMs. Default egress is a per-VM public IP (cheapest); egress_mode=nat_gateway provisions a shared NAT Gateway instead.—
failedFAILURENetwork workflow failedfailure_reason

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "network.azure.runner-segment.ensure",
  "initial_data": {
    "organization_uuid": "value",
    "connection_uuid": "value",
    "resource_group": "value",
    "location": "value"
  }
}