runner.environment-drift-detect ​
Detect environment drift for a runner group across all backends
Detect infrastructure drift for a runner group environment.
Produces a RunnerEnvironmentDriftPlan. This workflow is read-only / dry-run by default: auto_apply defaults to False, so a plain detect call NEVER mutates infrastructure. Only when the caller explicitly passes auto_apply=True and drift is found does it chain the mutating runner.environment-drift-repair workflow.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-runners |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | Yes | — | UUID of the RunnerGroup to detect drift for, picked from the organization's list of runner groups. |
organization_uuid | uuid | Yes | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
auto_apply | boolean | No | False | When True, and drift is found, automatically chains the mutating runner.environment-drift-repair workflow (which creates/repairs ECS cluster, log group, task definition, GCE service account / instance template, Cloud Run job). Defaults to False: a detect call is dry-run / read-only and never mutates infrastructure unless auto_apply is explicitly set True. |
trace_ref | string | No | — | — |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | No | — | UUID of the RunnerGroup this action operates on, picked from the organization's list of runner groups; echoed on output alongside terminal/error payloads. |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. Echoed on output alongside terminal/error payloads. |
runner_execution_uuid | uuid | No | — | UUID of the RunnerExecution this action operates on, picked from the organization's (optionally group-scoped) list of executions; echoed on output alongside terminal/error payloads. |
workflow_uuid | string | No | — | Engine workflow-run identifier (or, for GitHub-Actions-triggered flows, an external GitHub Actions run id) associated with this record; not a platform entity foreign key despite the name. No source is attached since there is no list/query workflow for an internal run id. |
status | string | No | — | — |
outcome | string | No | — | — |
initiated_at | string | No | — | — |
completed_at | string | No | — | — |
failed_at | string | No | — | — |
failure_reason | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
actor_uuid | uuid | No | — | UUID of the user or service actor who triggered this action, injected server-side from the authenticated request when available; used for audit/attribution only. Optional — omitted for system or service-triggered actions with no human actor. |
reason | string | No | — | — |
workflow_run_uuid | string | No | — | Engine-stamped correlation/run id for this DAG execution (ADR-015/E1 plumbing), written into state_data by action_start; not a foreign key to any business entity. No source is attached since there is no list/query workflow for an internal run id. |
retry_count | integer | No | — | — |
retried_from | string | No | — | — |
failed_step | json | No | — | — |
failed_layer | json | No | — | — |
failed_at_state | json | No | — | — |
compensation_trigger | json | No | — | — |
comp_current_layer | json | No | — | — |
comp_queue | json | No | — | — |
comp_retry_count | json | No | — | — |
plan_uuid | uuid | No | — | UUID of the RunnerEnvironmentDriftPlan produced by runner.environment-drift-detect. NOT a subscription/billing plan — the platform-wide field name 'plan_uuid' otherwise collides with ltinteg-workflow-app-subscription-library's field_sources.py registry entry (data.subscription.plan.list); this inline source overrides that. Pass this UUID to runner.environment-drift-repair. |
plan_status | string | No | — | One of: clean |
repair_workflow_uuid | string | No | — | Set when auto_apply=True and a repair workflow was chained. Engine workflow-run identifier for that chained run; not a platform entity foreign key despite the name. System-generated, no backing entity or list-workflow, so no source is attached by design. |
auto_apply | boolean | No | — | — |
trace_ref | string | No | — | — |
backend_type | string | No | — | — |
cloud_connection_uuid | uuid | No | — | UUID of the CloudConnection backing this runner group's cloud backend, picked from the organization's connections. Optional: omitted when the group has no connection yet. |
actions_needed | list | No | — | — |
blocked_resources | list | No | — | — |
drift_summary | dict | No | — | — |
drift_detect_init | json | No | — | — |
drift_detect_ecs_cluster | json | No | — | — |
drift_detect_log_group | json | No | — | — |
drift_detect_task_definition | json | No | — | — |
drift_detect_pull_secret | json | No | — | — |
drift_detect_gce_service_account | json | No | — | — |
drift_detect_gce_instance_template | json | No | — | — |
drift_detect_cloud_run_job | json | No | — | — |
drift_build_plan | json | No | — | — |
drift_finalize | json | No | — | — |
DAG Layers ​
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | init | runner.drift_detect_init | — |
| 2 | detect | runner.drift_detect_ecs_cluster, runner.drift_detect_log_group, runner.drift_detect_task_definition, runner.drift_detect_pull_secret, runner.drift_detect_gce_service_account, runner.drift_detect_gce_instance_template, runner.drift_detect_cloud_run_job | — |
| 3 | plan | runner.drift_build_plan | — |
| 4 | finalize | runner.drift_finalize | — |
Execution Flow ​
Sub-workflows ​
| Sub-workflow | Step name |
|---|---|
runner.drift_detect_init | drift_detect_init |
runner.drift_detect_ecs_cluster | drift_detect_ecs_cluster |
runner.drift_detect_log_group | drift_detect_log_group |
runner.drift_detect_task_definition | drift_detect_task_definition |
runner.drift_detect_pull_secret | drift_detect_pull_secret |
runner.drift_detect_gce_service_account | drift_detect_gce_service_account |
runner.drift_detect_gce_instance_template | drift_detect_gce_instance_template |
runner.drift_detect_cloud_run_job | drift_detect_cloud_run_job |
runner.drift_build_plan | drift_build_plan |
runner.drift_finalize | drift_finalize |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "runner.environment-drift-detect",
"initial_data": {
"runner_group_uuid": "value",
"organization_uuid": "value"
}
}