Skip to content
Proud to collaborate with Microsoft for Startups

runner.execution-launch-cloud-run-gitlab ​

Launch one GitLab CI runner execution on Cloud Run

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-runners-gcp
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidYes—Runner group UUID
organization_uuiduuidNo—Organization UUID (validated against runner group)
runner_execution_uuiduuidNo—Existing execution UUID to reuse
environmentdictNo—Environment variables passed to the container. Vaulted (engine >=1.12.0): persisted state_data holds a [VAULT:...] reference, never the values. Still prefer secret_environment for credentials — it keeps them out of the job spec entirely
secret_environmentdictNo—Env vars bound to Secret Manager refs (env_var -> secret id or {secret, version}); rendered as secretKeyRef so values stay out of the job spec/audit log
staged_secret_idslistNo—Ephemeral Secret Manager ids minted by runner.execution-secret-stage-gcp for this execution; deleted when the execution goes terminal
commandstringNo—Command override (generic executions only)
extra_labelsdictNo—Additional GCP labels for the Cloud Run job (lowercase keys enforced, e.g. agent-session-id)

Output Schema ​

FieldTypeRequiredDefaultDescription
runner_execution_uuiduuidYes—RunnerExecution row this workflow drove
runner_group_uuiduuidNo—Runner group the execution belongs to
organization_uuiduuidNo—Organization UUID (validated against runner group)
commandstringNo—Command override (generic executions only)
environmentdictNo—Environment variables passed to the container (vaulted — persisted state_data holds a [VAULT:...] reference)
secret_environmentdictNo—Env vars bound to Secret Manager refs (secretKeyRef); values stay out of the job spec/audit log
staged_secret_idslistNo—Ephemeral Secret Manager ids minted for this execution; deleted at terminal state
extra_labelsdictNo—Additional GCP labels for the Cloud Run job
provider_execution_idstringNo—Cloud Run job execution reference
registration_tokenstringNo—GitHub registration token (when applicable)
permission_preflightjsonNo—GCP IAM permission preflight check result
mirror_tuplejsonNo—Internal handoff: Cloud Run registry mirror tuple resolved by precheck_mirror and consumed by launch_execution to rewrite the container image path; null when no mirror rewrite is required
completed_atstringNo—ISO timestamp when launch finalised
failed_atstringNo—ISO timestamp when launch failed
failure_reasonstringNo—Populated only when the workflow ends in FAILED
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
initiatedYesNo—prepare—
getting_registration_tokenNoNo—precheck_permissions—
launching_executionNoNo—complete—
prechecking_mirrorNoNo—get_registration_token—
prechecking_permissionsNoNo—launch_execution—
preparingNoNo—precheck_mirror—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
initiatedpreparepreparing—
preparingprecheck_mirrorprechecking_mirror—
prechecking_mirrorget_registration_tokengetting_registration_token—
getting_registration_tokenprecheck_permissionsprechecking_permissions—
prechecking_permissionslaunch_executionlaunching_execution—
launching_executioncompletecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "runner.execution-launch-cloud-run-gitlab",
  "initial_data": {
    "runner_group_uuid": "value"
  }
}