runner.acr-registry-mirror-reconcile ​
Reconcile an ACR cache-rule mirror to its expected state
Overview ​
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-runners-azure |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | Yes | — | Runner group the mirror belongs to. |
organization_uuid | uuid | No | — | Organization UUID; resolved from the group when omitted. |
workflow_run_id | string | No | — | DAG step parent run ID (stamped by engine) |
workflow_run_uuid | string | No | — | Engine-stamped correlation/run id (ADR-015) |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | No | — | Runner group echoed from input. |
organization_uuid | uuid | No | — | Organization UUID resolved for the group. |
registry_name | string | No | — | Target Azure Container Registry. |
resource_group | string | No | — | Resource group holding the registry. |
upstream_url | string | No | — | Upstream registry the mirror fronts. |
mirror_uuid | uuid | No | — | AcrRegistryMirror row this run operates on. |
mirror_status | string | No | — | Terminal mirror status. |
ready | boolean | No | — | True when the mirror is usable by launches. |
completed_at | string | No | — | ISO timestamp when the operation finalised. |
validate | json | No | — | Output of the validate DAG step. |
secret | json | No | — | Output of the secret DAG step. |
grant_iam | json | No | — | Output of the grant_iam DAG step. |
repository | json | No | — | Output of the repository DAG step. |
verify | json | No | — | Output of the verify DAG step. |
finalize | json | No | — | Output of the finalize DAG step. |
workflow_run_id | string | No | — | — |
failure_type | string | No | — | — |
failure_reason | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | json | No | — | — |
failed_at_state | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
failed_at | string | No | — | — |
DAG Layers ​
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | validate | runner.validate_acr_registry_mirror | — |
| 2 | secret | runner.ensure_acr_mirror_secret | runner.acr-registry-mirror-teardown |
| 3 | grant_iam | runner.grant_acr_credential_set_secret_access | — |
| 4 | repository | runner.ensure_acr_mirror_repository | runner.acr-registry-mirror-teardown |
| 5 | verify | runner.verify_acr_registry_mirror | — |
| 6 | finalize | runner.finalize_acr_registry_mirror | — |
Execution Flow ​
Compensation ​
When any layer fails, its compensation steps run in reverse order to roll back the work completed so far.
Sub-workflows ​
| Sub-workflow | Step name |
|---|---|
runner.validate_acr_registry_mirror | validate |
runner.ensure_acr_mirror_secret | secret |
runner.grant_acr_credential_set_secret_access | grant_iam |
runner.ensure_acr_mirror_repository | repository |
runner.verify_acr_registry_mirror | verify |
runner.finalize_acr_registry_mirror | finalize |
runner.acr-registry-mirror-teardown | teardown_partial |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "runner.acr-registry-mirror-reconcile",
"initial_data": {
"runner_group_uuid": "value"
}
}