runner.cloud-run-registry-mirror-ensure ​
Ensure an Artifact Registry mirror exists for a Cloud Run upstream
Ensure an Artifact Registry remote-repo mirror exists and is verified.
Layers:
- validate — resolve coordinates, upsert
CloudRunRegistryMirrorrow - secret — upsert Secret Manager secret + grant AR service-agent access
- repository — upsert AR remote repository, update on drift
- verify — describe the repo, refresh
last_verified_at - finalize — flip status to
READY
Overview ​
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-runners-gcp |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | Yes | — | RunnerGroup UUID whose Cloud Run image needs a mirror |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
upstream_url | string | No | — | Upstream registry URL (e.g. https://ghcr.io). Derived from runner_group.config.container_image when omitted. |
workflow_run_id | string | No | — | Engine-stamped workflow run ID |
workflow_run_uuid | string | No | — | Engine-stamped correlation/run id (ADR-015/E1); tolerated on input |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | Yes | — | Runner group whose mirror was ensured |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
upstream_url | string | No | — | Upstream registry URL the mirror fronts |
workflow_run_id | string | No | — | Engine-stamped workflow run ID |
workflow_run_uuid | string | No | — | Internal engine correlation/run identifier for this DAG execution (ADR-015/E1); not a reference to any business entity. |
mirror_uuid | uuid | No | — | CloudRunRegistryMirror UUID created or reused (output-only echo). No data.*.list/get workflow exists for this entity anywhere in the platform, so no source picker is attached. |
project_id | string | No | — | GCP project ID hosting the Artifact Registry remote repo |
region | string | No | — | Artifact Registry region |
repository_id | string | No | — | Artifact Registry repository ID |
secret_id | string | No | — | Secret Manager secret ID holding upstream credentials (when needed) |
failure_reason | string | No | — | Populated only when the workflow ends in FAILED |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
validate_mirror | json | No | — | Output of the validate_mirror DAG step |
ensure_secret | json | No | — | Output of the ensure_secret DAG step |
grant_iam | json | No | — | Output of the grant_iam DAG step |
ensure_repository | json | No | — | Output of the ensure_repository DAG step |
verify_mirror | json | No | — | Output of the verify_mirror DAG step |
finalize_mirror | json | No | — | Output of the finalize_mirror DAG step |
DAG Layers ​
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | validate | runner.validate_cloud_run_registry_mirror | — |
| 2 | secret | runner.ensure_cloud_run_mirror_secret | — |
| 3 | grant_iam | runner.grant_ar_service_agent_secret_access | — |
| 4 | repository | runner.ensure_cloud_run_mirror_repository | — |
| 5 | verify | runner.verify_cloud_run_registry_mirror | — |
| 6 | finalize | runner.finalize_cloud_run_registry_mirror | — |
Execution Flow ​
Sub-workflows ​
| Sub-workflow | Step name |
|---|---|
runner.validate_cloud_run_registry_mirror | validate_mirror |
runner.ensure_cloud_run_mirror_secret | ensure_secret |
runner.grant_ar_service_agent_secret_access | grant_iam |
runner.ensure_cloud_run_mirror_repository | ensure_repository |
runner.verify_cloud_run_registry_mirror | verify_mirror |
runner.finalize_cloud_run_registry_mirror | finalize_mirror |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "runner.cloud-run-registry-mirror-ensure",
"initial_data": {
"runner_group_uuid": "value"
}
}