registry.kubernetes-pull-binding.reconcile ​
Mint a dockerconfigjson pull Secret from a registry account and attach it to ServiceAccounts in selected namespaces
Reconcile a registry pull Secret onto selected namespaces of a Kubernetes connection. Mints docker-login credentials in-process from the registry account (or its GitHub connection) and never echoes them.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-kubernetes |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
connection_uuid | uuid | Yes | — | Kubernetes cluster connection to apply the pull Secret on. |
namespaces | list | Yes | — | Namespaces that receive the pull Secret. MASTER is refused. |
secret_name | string | No | — | Secret name. Defaults to ghcr-pull. |
registry_account_uuid | uuid | No | — | RegistryAccount that yields docker-login credentials. |
github_connection_uuid | uuid | No | — | GitHub connection used by the GHCR RegistryAccount when registry_account_uuid is omitted. |
service_account_names | list | No | — | ServiceAccounts to attach. Defaults to default and relay-runtime. |
organization_uuid | uuid | No | — | — |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
connection_uuid | uuid | No | — | — |
organization_uuid | uuid | No | — | — |
registry_account_uuid | uuid | No | — | — |
github_connection_uuid | uuid | No | — | — |
secret_name | string | No | — | — |
namespaces | list | No | — | — |
service_account_names | list | No | — | — |
secrets_applied | integer | No | — | — |
service_accounts_attached | integer | No | — | — |
reconciled_at | string | No | — | — |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "registry.kubernetes-pull-binding.reconcile",
"initial_data": {
"connection_uuid": "value",
"namespaces": "value"
}
}