runner.cloud-run-registry-mirror-teardown ​
Delete an AR remote-repo mirror + backing secret (operator-only)
Operator-only teardown of a Cloud Run registry mirror.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Linear |
| Library | App-runners-gcp |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
mirror_uuid | uuid | Yes | — | CloudRunRegistryMirror UUID to tear down. No data.*.list/get workflow exists for this entity anywhere in the platform, so this is a required manual input with no picker — the caller must already know the UUID (e.g. from the CloudRunRegistryMirror row created by runner.cloud-run-registry-mirror-ensure). |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; validated against the mirror's cloud connection. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
mirror_uuid | uuid | Yes | — | CloudRunRegistryMirror that was torn down (output-only echo). No data.*.list/get workflow exists for this entity anywhere in the platform, so no source picker is attached. |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; validated against the mirror's cloud connection. |
project_id | string | No | — | GCP project ID the mirror lived in |
region | string | No | — | Artifact Registry region |
repository_id | string | No | — | Artifact Registry repository ID that was deleted |
secret_id | string | No | — | Secret Manager secret ID that was deleted (when present) |
sample_runner_group_uuid | uuid | No | — | A Cloud Run RunnerGroup on the same cloud connection, auto-selected by the workflow itself (not the caller) to borrow LTIP credentials for the delete calls; no source picker needed since this is never a caller-supplied input. |
repository_deleted_at | string | No | — | ISO timestamp when the AR repository was deleted |
secret_deleted_at | string | No | — | ISO timestamp when the Secret Manager secret was deleted |
finalized_at | string | No | — | ISO timestamp the teardown finalised |
completed_at | string | No | — | ISO timestamp the workflow completed |
failed_at | string | No | — | ISO timestamp when teardown failed |
failure_reason | string | No | — | Populated only when the workflow ends in FAILED |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
initiated | Yes | No | — | validate | — |
deleting_repository | No | No | — | delete_secret | — |
deleting_secret | No | No | — | finalize | — |
finalizing | No | No | — | complete | — |
validating | No | No | — | delete_repository | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
initiated | validate | validating | — |
validating | delete_repository | deleting_repository | — |
deleting_repository | delete_secret | deleting_secret | — |
deleting_secret | finalize | finalizing | — |
finalizing | complete | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "runner.cloud-run-registry-mirror-teardown",
"initial_data": {
"mirror_uuid": "value"
}
}