runner.create_gce_service_account ​
Resolve / create / bind a GCP service account for runner VMs.
Provision the GCE runner service account, gated by config.service_account_mode.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-runners-gcp |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | Yes | — | UUID of the RunnerGroup this action operates on, picked from the organization's list of runner groups. |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
project_id | string | No | — | — |
workflow_run_id | string | No | — | Engine-stamped workflow run ID |
workflow_run_uuid | string | No | — | Engine-stamped correlation/run id (ADR-015/E1); tolerated on input |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | No | — | UUID of the RunnerGroup whose GCE service account was resolved, echoed back from the input. |
organization_uuid | uuid | No | — | UUID of the caller's organization, echoed back from the input. |
cloud_connection_uuid | uuid | No | — | UUID of the GCP CloudConnection backing this runner group's cloud backend, picked from the organization's GCP connections. |
project_id | string | No | — | — |
mode | string | No | — | Service account mode: default, byo, or managed |
service_account_email | string | No | — | Resolved runner VM service account email |
workflow_run_uuid | string | No | — | Internal engine correlation/run identifier for this DAG execution, stamped by the engine (ADR-015/E1). |
failure_reason | string | No | — | Populated only when the workflow ends in FAILED |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
pre | json | No | — | Output of the pre DAG step |
project_describe | json | No | — | Output of the project_describe DAG step |
sa_create | json | No | — | Output of the sa_create DAG step |
iam_binding | json | No | — | Output of the iam_binding DAG step |
post | json | No | — | Output of the post DAG step |
DAG Layers ​
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | pre | runner.create_gce_service_account__pre | — |
| 2 | project_describe | gcp.compute.project.describe | — |
| 3 | sa_create | gcp.iam.service_account.create | — |
| 4 | iam_binding | gcp.iam.binding.create | — |
| 5 | post | runner.create_gce_service_account__post | — |
Execution Flow ​
Sub-workflows ​
| Sub-workflow | Step name |
|---|---|
runner.create_gce_service_account__pre | pre |
gcp.compute.project.describe | project_describe |
gcp.iam.service_account.create | sa_create |
gcp.iam.binding.create | iam_binding |
runner.create_gce_service_account__post | post |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "runner.create_gce_service_account",
"initial_data": {
"runner_group_uuid": "value"
}
}