runner.environment-provision-ec2-vm ​
Provision a raw EC2 VM environment for a runner group
Provision a raw EC2 VM runner environment for a runner group.
Layers:
- validate — check subscription + required config, set PROVISIONING
- iam — create/validate the VM instance profile (SSM + CloudWatch)
- log_group — create the CloudWatch log group (/ltinteg/runners/<id>) then apply its retention policy (separate AWS call)
- launch_template — create the instance-shape launch template
- register_github — register the GitHub runner group (no-op for non-GITHUB)
- finalize — persist cached fields + config handles, set ACTIVE
The iam layer must precede launch_template: the template embeds the instance profile ARN the iam layer produces.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-runners-aws |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | Yes | — | UUID of the RunnerGroup whose raw EC2 VM environment is being provisioned, picked from the organization's list of runner groups. |
organization_uuid | uuid | Yes | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
registry_account_uuid | uuid | No | — | UUID of the container registry account this runner group resolves images against, picked from the organization's registry accounts. Optional — falls back to default/unauthenticated image resolution when absent. |
workflow_run_id | string | No | — | — |
workflow_run_uuid | string | No | — | Internal engine correlation/run identifier stamped onto this DAG execution; not a user-facing entity reference and has no picker. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | No | — | UUID of the RunnerGroup this workflow operates on, picked from the organization's list of runner groups. Optional on this shared passthrough schema because the same field also appears as an output-only echo. |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
registry_account_uuid | uuid | No | — | UUID of the container registry account this runner group resolves images against, picked from the organization's registry accounts. Optional — falls back to default/unauthenticated image resolution when absent. |
actor_uuid | uuid | No | — | UUID of the user or service actor who triggered this action, injected server-side from the authenticated request when available; used for audit/attribution only. |
workflow_run_id | string | No | — | — |
workflow_run_uuid | string | No | — | Legacy alias of workflow_run_id: an internal engine correlation/run identifier for this DAG execution (ADR-015/E1 plumbing), not a foreign key to any business entity. No list/query workflow applies — this is engine-generated, never user-supplied. |
workflow_uuid | string | No | — | Engine workflow-run identifier associated with this record; not a platform entity foreign key despite the name. No list/query workflow applies — this is engine-generated, never user-supplied. |
status | string | No | — | — |
outcome | string | No | — | — |
initiated_at | string | No | — | — |
completed_at | string | No | — | — |
failed_at | string | No | — | — |
failure_reason | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
reason | string | No | — | — |
failed_step | json | No | — | — |
failed_layer | json | No | — | — |
failed_at_state | json | No | — | — |
compensation_trigger | json | No | — | — |
comp_current_layer | json | No | — | — |
comp_queue | json | No | — | — |
comp_retry_count | json | No | — | — |
primitive_input | json | No | — | — |
primitive_output | json | No | — | — |
validate_ec2_vm_environment | json | No | — | — |
create_ec2_vm_iam_instance_profile | json | No | — | — |
create_ec2_vm_log_group | json | No | — | — |
set_log_group_retention | json | No | — | — |
create_ec2_vm_launch_template | json | No | — | — |
register_github_runner_group | json | No | — | — |
finalize_ec2_vm_environment | json | No | — | — |
DAG Layers ​
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | validate | runner.validate_ec2_vm_environment | — |
| 2 | iam | runner.create_ec2_vm_iam_instance_profile | — |
| 3 | log_group | runner.create_ec2_vm_log_group | — |
| 4 | log_retention | runner.set_log_group_retention | — |
| 5 | launch_template | runner.create_ec2_vm_launch_template | — |
| 6 | register_github | runner.register_github_runner_group | — |
| 7 | finalize | runner.finalize_ec2_vm_environment | — |
Execution Flow ​
Sub-workflows ​
| Sub-workflow | Step name |
|---|---|
runner.validate_ec2_vm_environment | validate_ec2_vm_environment |
runner.create_ec2_vm_iam_instance_profile | create_ec2_vm_iam_instance_profile |
runner.create_ec2_vm_log_group | create_ec2_vm_log_group |
runner.set_log_group_retention | set_log_group_retention |
runner.create_ec2_vm_launch_template | create_ec2_vm_launch_template |
runner.register_github_runner_group | register_github_runner_group |
runner.finalize_ec2_vm_environment | finalize_ec2_vm_environment |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "runner.environment-provision-ec2-vm",
"initial_data": {
"runner_group_uuid": "value",
"organization_uuid": "value"
}
}