runner.drift_repair_gce_service_account ​
Repair drift: create managed GCE service account
Repair the GCE service account for a GCE runner group (managed mode only).
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-runners-gcp |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | Yes | — | UUID of the RunnerGroup to repair drift for, picked from the organization's list of runner groups. |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
cloud_connection_uuid | uuid | No | — | UUID of the CloudConnection backing this runner group's cloud backend, picked from the organization's connections. |
backend_type | string | No | — | — |
actions_needed | list | Yes | — | — |
workflow_run_id | string | No | — | Engine-stamped workflow run ID |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | No | — | UUID of the RunnerGroup this drift action operates on, picked from the organization's list of runner groups. |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
backend_type | string | No | — | — |
workflow_run_id | string | No | — | Engine-stamped workflow run ID |
runner_execution_uuid | uuid | No | — | UUID of the RunnerExecution this drift action operates on, picked from the organization's (optionally group-scoped) list of executions. |
status | string | No | — | — |
outcome | string | No | — | — |
initiated_at | string | No | — | — |
completed_at | string | No | — | — |
failed_at | string | No | — | — |
failure_reason | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
actor_uuid | uuid | No | — | UUID of the user or service actor who triggered this action, injected server-side from the authenticated request; used for audit/attribution only. |
reason | string | No | — | — |
workflow_run_uuid | uuid | No | — | Internal engine-stamped correlation/run identifier for this DAG execution; not a foreign key to any business entity, so no source picker is attached. |
retry_count | integer | No | — | — |
retried_from | string | No | — | — |
failed_step | json | No | — | — |
failed_layer | json | No | — | — |
failed_at_state | json | No | — | — |
compensation_trigger | json | No | — | — |
comp_current_layer | json | No | — | — |
comp_queue | json | No | — | — |
comp_retry_count | json | No | — | — |
cloud_connection_uuid | uuid | No | — | UUID of the CloudConnection backing this runner group's cloud backend, echoed through from input, picked from the organization's connections. |
actions_needed | list | No | — | — |
resource_type | string | No | — | — |
skipped | boolean | No | — | — |
applied_action | string | No | — | — |
sub_workflow_uuid | uuid | No | — | Internal engine run id of a child workflow this drift-repair step chained while applying its fix (e.g. token-resolve or re-provision); not a user-facing entity reference, so no source picker is attached. |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "runner.drift_repair_gce_service_account",
"initial_data": {
"runner_group_uuid": "value",
"actions_needed": "value"
}
}