runner.execution-launch-azure-container-apps ​
Launch one runner execution on Azure Container Apps Jobs
Overview ​
| Property | Value |
|---|---|
| Workflow type | Linear |
| Library | App-runners-azure |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | No | — | Runner group UUID for the execution |
organization_uuid | uuid | No | — | Organization UUID for the runner group |
runner_execution_uuid | uuid | Yes | — | Runner execution UUID to launch |
command | json | No | — | Command override to execute |
environment | json | No | — | Environment variables to pass to the runner. Marked sensitive so SensitiveDataMiddleware vaults the map instead of persisting it in cleartext state_data (SECRET-HANDLING-001). Prefer secret_environment for credentials: vaulting protects state_data only, while the outbound scheduled-transition/Kafka input_data copy still carries cleartext until the engine's input_data redaction writer is enabled. |
secret_environment | json | No | — | Credential-bearing environment variables, as {ENV_NAME: Azure Key Vault secret URI}. Bound to the job via Container Apps secretRef — the value is resolved by Azure at replica start and never enters workflow state. |
github_workflow_run_ref | integer | No | — | GitHub Actions run id for correlation; sent by runner.dispatch-from-job-queued on the legacy direct-launch path. |
actor_uuid | string | No | — | Actor attribution forwarded by the dispatcher; audit-only. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | string | No | — | UUID of the RunnerGroup this action operates on, echoed onto workflow state; picked from the organization's list of runner groups. |
runner_execution_uuid | string | No | — | UUID of the RunnerExecution this action operates on, echoed onto workflow state; picked from the organization's (optionally group-scoped) list of executions. |
registration_token | string | No | — | Ephemeral provider runner-registration token. Marked sensitive so SensitiveDataMiddleware vaults it instead of persisting it in cleartext state_data (SECRET-HANDLING-001). |
provider_execution_ref | string | No | — | — |
completed_at | string | No | — | — |
failed_at | string | No | — | — |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
initiated | Yes | No | — | load_execution | — |
getting_registration_token | No | No | — | launch_execution | — |
launching_execution | No | No | — | complete | — |
loading_execution | No | No | — | get_registration_token | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
initiated | load_execution | loading_execution | — |
loading_execution | get_registration_token | getting_registration_token | — |
getting_registration_token | launch_execution | launching_execution | — |
launching_execution | complete | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "runner.execution-launch-azure-container-apps",
"initial_data": {
"runner_execution_uuid": "value"
}
}