Skip to content
Proud to collaborate with Microsoft for Startups

runner.cloud-run-registry-mirror-ensure ​

Ensure an Artifact Registry mirror exists for a Cloud Run upstream

Ensure an Artifact Registry remote-repo mirror exists and is verified.

Layers:

  1. validate — resolve coordinates, upsert CloudRunRegistryMirror row
  2. secret — upsert Secret Manager secret + grant AR service-agent access
  3. repository — upsert AR remote repository, update on drift
  4. verify — describe the repo, refresh last_verified_at
  5. finalize — flip status to READY

Overview ​

PropertyValue
Workflow typeDag
LibraryApp-runners-gcp
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidYes—RunnerGroup UUID whose Cloud Run image needs a mirror
organization_uuiduuidNo—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant.
upstream_urlstringNo—Upstream registry URL (e.g. https://ghcr.io). Derived from runner_group.config.container_image when omitted.
workflow_run_idstringNo—Engine-stamped workflow run ID
workflow_run_uuidstringNo—Engine-stamped correlation/run id (ADR-015/E1); tolerated on input

Output Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidYes—Runner group whose mirror was ensured
organization_uuiduuidNo—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant.
upstream_urlstringNo—Upstream registry URL the mirror fronts
workflow_run_idstringNo—Engine-stamped workflow run ID
workflow_run_uuidstringNo—Internal engine correlation/run identifier for this DAG execution (ADR-015/E1); not a reference to any business entity.
mirror_uuiduuidNo—CloudRunRegistryMirror UUID created or reused (output-only echo). No data.*.list/get workflow exists for this entity anywhere in the platform, so no source picker is attached.
project_idstringNo—GCP project ID hosting the Artifact Registry remote repo
regionstringNo—Artifact Registry region
repository_idstringNo—Artifact Registry repository ID
secret_idstringNo—Secret Manager secret ID holding upstream credentials (when needed)
failure_reasonstringNo—Populated only when the workflow ends in FAILED
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——
validate_mirrorjsonNo—Output of the validate_mirror DAG step
ensure_secretjsonNo—Output of the ensure_secret DAG step
grant_iamjsonNo—Output of the grant_iam DAG step
ensure_repositoryjsonNo—Output of the ensure_repository DAG step
verify_mirrorjsonNo—Output of the verify_mirror DAG step
finalize_mirrorjsonNo—Output of the finalize_mirror DAG step

DAG Layers ​

#LayerStepsCompensation
1validaterunner.validate_cloud_run_registry_mirror—
2secretrunner.ensure_cloud_run_mirror_secret—
3grant_iamrunner.grant_ar_service_agent_secret_access—
4repositoryrunner.ensure_cloud_run_mirror_repository—
5verifyrunner.verify_cloud_run_registry_mirror—
6finalizerunner.finalize_cloud_run_registry_mirror—

Execution Flow ​

Sub-workflows ​

Sub-workflowStep name
runner.validate_cloud_run_registry_mirrorvalidate_mirror
runner.ensure_cloud_run_mirror_secretensure_secret
runner.grant_ar_service_agent_secret_accessgrant_iam
runner.ensure_cloud_run_mirror_repositoryensure_repository
runner.verify_cloud_run_registry_mirrorverify_mirror
runner.finalize_cloud_run_registry_mirrorfinalize_mirror

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "runner.cloud-run-registry-mirror-ensure",
  "initial_data": {
    "runner_group_uuid": "value"
  }
}