Skip to content
Proud to collaborate with Microsoft for Startups

runner.execution-secret-stage-gcp ​

Stage runner environment values into GCP Secret Manager and return secretKeyRef references

Stage runner env-var values into GCP Secret Manager and return references.

Input secret_values carries plaintext and is marked sensitive=True, so SensitiveDataMiddleware vaults it and the persisted state_data holds a [VAULT:...] reference instead of the values. This requires ltinteg-workflow-engine >= 1.12.0, which serialises non-string vault values through a tagged JSON envelope; older engines raise AttributeError inside after_start and terminalise the run. The floor is declared in pyproject.toml and guarded by tests/test_runners_gcp_secret_handling_contract.py.

Vaulting is defence in depth, not the primary control. The workflow's real protection is structural: secret_values is never echoed onto its own output contract and never written to execution_metadata — only the resulting Secret Manager references leave this workflow, and those are what the launcher binds as secretKeyRef so the values never enter a job spec.

Output secret_environment carries only Secret Manager ids and is safe to feed straight into runner.execution-launch-cloud-run.

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-runners-gcp
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidYes—Runner group whose GCP connection/project hosts the staged secrets
organization_uuiduuidNo—Organization UUID (validated against runner group)
runner_execution_uuiduuidNo—Execution the secrets belong to; scopes secret ids and records them for teardown
secret_valuesdictYes—env_var_name -> secret VALUE. Vaulted (engine >=1.12.0): persisted state_data holds a [VAULT:...] reference. Written to Secret Manager; never echoed onto the output contract and never written to execution_metadata
service_account_emailstringNo—Runner service account granted roles/secretmanager.secretAccessor (defaults to the runner group's config.service_account)

Output Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidNo—Runner group the secrets were staged for
organization_uuiduuidNo—Organization UUID (validated against runner group)
runner_execution_uuiduuidNo—Execution the secrets were staged for
secret_environmentdictNo—env_var_name -> Secret Manager secret id; pass to the launch workflow
staged_secret_idslistNo—Ephemeral secret ids minted here; deleted when the execution goes terminal
service_account_emailstringNo—Principal granted roles/secretmanager.secretAccessor on each staged secret
staged_countintegerNo—Number of env vars staged
completed_atstringNo—ISO timestamp when staging finalised
failed_atstringNo—ISO timestamp when staging failed
failure_reasonstringNo—Populated only when the workflow ends in FAILED
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
initiatedYesNo—stage_secrets—
staging_secretsNoNo—complete—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
initiatedstage_secretsstaging_secrets—
staging_secretscompletecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "runner.execution-secret-stage-gcp",
  "initial_data": {
    "runner_group_uuid": "value",
    "secret_values": "value"
  }
}