Skip to content
Proud to collaborate with Microsoft for Startups

runner.environment-provision-ec2-vm ​

Provision a raw EC2 VM environment for a runner group

Provision a raw EC2 VM runner environment for a runner group.

Layers:

  1. validate — check subscription + required config, set PROVISIONING
  2. iam — create/validate the VM instance profile (SSM + CloudWatch)
  3. log_group — create the CloudWatch log group (/ltinteg/runners/<id>) then apply its retention policy (separate AWS call)
  4. launch_template — create the instance-shape launch template
  5. register_github — register the GitHub runner group (no-op for non-GITHUB)
  6. finalize — persist cached fields + config handles, set ACTIVE

The iam layer must precede launch_template: the template embeds the instance profile ARN the iam layer produces.

Overview ​

PropertyValue
Workflow typeDag
LibraryApp-runners-aws
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidYes—UUID of the RunnerGroup whose raw EC2 VM environment is being provisioned, picked from the organization's list of runner groups.
organization_uuiduuidYes—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant.
registry_account_uuiduuidNo—UUID of the container registry account this runner group resolves images against, picked from the organization's registry accounts. Optional — falls back to default/unauthenticated image resolution when absent.
workflow_run_idstringNo——
workflow_run_uuidstringNo—Internal engine correlation/run identifier stamped onto this DAG execution; not a user-facing entity reference and has no picker.

Output Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidNo—UUID of the RunnerGroup this workflow operates on, picked from the organization's list of runner groups. Optional on this shared passthrough schema because the same field also appears as an output-only echo.
organization_uuiduuidNo—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant.
registry_account_uuiduuidNo—UUID of the container registry account this runner group resolves images against, picked from the organization's registry accounts. Optional — falls back to default/unauthenticated image resolution when absent.
actor_uuiduuidNo—UUID of the user or service actor who triggered this action, injected server-side from the authenticated request when available; used for audit/attribution only.
workflow_run_idstringNo——
workflow_run_uuidstringNo—Legacy alias of workflow_run_id: an internal engine correlation/run identifier for this DAG execution (ADR-015/E1 plumbing), not a foreign key to any business entity. No list/query workflow applies — this is engine-generated, never user-supplied.
workflow_uuidstringNo—Engine workflow-run identifier associated with this record; not a platform entity foreign key despite the name. No list/query workflow applies — this is engine-generated, never user-supplied.
statusstringNo——
outcomestringNo——
initiated_atstringNo——
completed_atstringNo——
failed_atstringNo——
failure_reasonstringNo——
errorstringNo——
error_typestringNo——
reasonstringNo——
failed_stepjsonNo——
failed_layerjsonNo——
failed_at_statejsonNo——
compensation_triggerjsonNo——
comp_current_layerjsonNo——
comp_queuejsonNo——
comp_retry_countjsonNo——
primitive_inputjsonNo——
primitive_outputjsonNo——
validate_ec2_vm_environmentjsonNo——
create_ec2_vm_iam_instance_profilejsonNo——
create_ec2_vm_log_groupjsonNo——
set_log_group_retentionjsonNo——
create_ec2_vm_launch_templatejsonNo——
register_github_runner_groupjsonNo——
finalize_ec2_vm_environmentjsonNo——

DAG Layers ​

#LayerStepsCompensation
1validaterunner.validate_ec2_vm_environment—
2iamrunner.create_ec2_vm_iam_instance_profile—
3log_grouprunner.create_ec2_vm_log_group—
4log_retentionrunner.set_log_group_retention—
5launch_templaterunner.create_ec2_vm_launch_template—
6register_githubrunner.register_github_runner_group—
7finalizerunner.finalize_ec2_vm_environment—

Execution Flow ​

Sub-workflows ​

Sub-workflowStep name
runner.validate_ec2_vm_environmentvalidate_ec2_vm_environment
runner.create_ec2_vm_iam_instance_profilecreate_ec2_vm_iam_instance_profile
runner.create_ec2_vm_log_groupcreate_ec2_vm_log_group
runner.set_log_group_retentionset_log_group_retention
runner.create_ec2_vm_launch_templatecreate_ec2_vm_launch_template
runner.register_github_runner_groupregister_github_runner_group
runner.finalize_ec2_vm_environmentfinalize_ec2_vm_environment

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "runner.environment-provision-ec2-vm",
  "initial_data": {
    "runner_group_uuid": "value",
    "organization_uuid": "value"
  }
}