Skip to content
Proud to collaborate with Microsoft for Startups

runner.environment-drift-detect ​

Detect environment drift for a runner group across all backends

Detect infrastructure drift for a runner group environment.

Produces a RunnerEnvironmentDriftPlan. This workflow is read-only / dry-run by default: auto_apply defaults to False, so a plain detect call NEVER mutates infrastructure. Only when the caller explicitly passes auto_apply=True and drift is found does it chain the mutating runner.environment-drift-repair workflow.

Overview ​

PropertyValue
Workflow typeDag
LibraryApp-runners
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidYes—UUID of the RunnerGroup to detect drift for, picked from the organization's list of runner groups.
organization_uuiduuidYes—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant.
auto_applybooleanNoFalseWhen True, and drift is found, automatically chains the mutating runner.environment-drift-repair workflow (which creates/repairs ECS cluster, log group, task definition, GCE service account / instance template, Cloud Run job). Defaults to False: a detect call is dry-run / read-only and never mutates infrastructure unless auto_apply is explicitly set True.
trace_refstringNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidNo—UUID of the RunnerGroup this action operates on, picked from the organization's list of runner groups; echoed on output alongside terminal/error payloads.
organization_uuiduuidNo—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. Echoed on output alongside terminal/error payloads.
runner_execution_uuiduuidNo—UUID of the RunnerExecution this action operates on, picked from the organization's (optionally group-scoped) list of executions; echoed on output alongside terminal/error payloads.
workflow_uuidstringNo—Engine workflow-run identifier (or, for GitHub-Actions-triggered flows, an external GitHub Actions run id) associated with this record; not a platform entity foreign key despite the name. No source is attached since there is no list/query workflow for an internal run id.
statusstringNo——
outcomestringNo——
initiated_atstringNo——
completed_atstringNo——
failed_atstringNo——
failure_reasonstringNo——
errorstringNo——
error_typestringNo——
actor_uuiduuidNo—UUID of the user or service actor who triggered this action, injected server-side from the authenticated request when available; used for audit/attribution only. Optional — omitted for system or service-triggered actions with no human actor.
reasonstringNo——
workflow_run_uuidstringNo—Engine-stamped correlation/run id for this DAG execution (ADR-015/E1 plumbing), written into state_data by action_start; not a foreign key to any business entity. No source is attached since there is no list/query workflow for an internal run id.
retry_countintegerNo——
retried_fromstringNo——
failed_stepjsonNo——
failed_layerjsonNo——
failed_at_statejsonNo——
compensation_triggerjsonNo——
comp_current_layerjsonNo——
comp_queuejsonNo——
comp_retry_countjsonNo——
plan_uuiduuidNo—UUID of the RunnerEnvironmentDriftPlan produced by runner.environment-drift-detect. NOT a subscription/billing plan — the platform-wide field name 'plan_uuid' otherwise collides with ltinteg-workflow-app-subscription-library's field_sources.py registry entry (data.subscription.plan.list); this inline source overrides that. Pass this UUID to runner.environment-drift-repair.
plan_statusstringNo—One of: clean
repair_workflow_uuidstringNo—Set when auto_apply=True and a repair workflow was chained. Engine workflow-run identifier for that chained run; not a platform entity foreign key despite the name. System-generated, no backing entity or list-workflow, so no source is attached by design.
auto_applybooleanNo——
trace_refstringNo——
backend_typestringNo——
cloud_connection_uuiduuidNo—UUID of the CloudConnection backing this runner group's cloud backend, picked from the organization's connections. Optional: omitted when the group has no connection yet.
actions_neededlistNo——
blocked_resourceslistNo——
drift_summarydictNo——
drift_detect_initjsonNo——
drift_detect_ecs_clusterjsonNo——
drift_detect_log_groupjsonNo——
drift_detect_task_definitionjsonNo——
drift_detect_pull_secretjsonNo——
drift_detect_gce_service_accountjsonNo——
drift_detect_gce_instance_templatejsonNo——
drift_detect_cloud_run_jobjsonNo——
drift_build_planjsonNo——
drift_finalizejsonNo——

DAG Layers ​

#LayerStepsCompensation
1initrunner.drift_detect_init—
2detectrunner.drift_detect_ecs_cluster, runner.drift_detect_log_group, runner.drift_detect_task_definition, runner.drift_detect_pull_secret, runner.drift_detect_gce_service_account, runner.drift_detect_gce_instance_template, runner.drift_detect_cloud_run_job—
3planrunner.drift_build_plan—
4finalizerunner.drift_finalize—

Execution Flow ​

Sub-workflows ​

Sub-workflowStep name
runner.drift_detect_initdrift_detect_init
runner.drift_detect_ecs_clusterdrift_detect_ecs_cluster
runner.drift_detect_log_groupdrift_detect_log_group
runner.drift_detect_task_definitiondrift_detect_task_definition
runner.drift_detect_pull_secretdrift_detect_pull_secret
runner.drift_detect_gce_service_accountdrift_detect_gce_service_account
runner.drift_detect_gce_instance_templatedrift_detect_gce_instance_template
runner.drift_detect_cloud_run_jobdrift_detect_cloud_run_job
runner.drift_build_plandrift_build_plan
runner.drift_finalizedrift_finalize

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "runner.environment-drift-detect",
  "initial_data": {
    "runner_group_uuid": "value",
    "organization_uuid": "value"
  }
}