Skip to content
Proud to collaborate with Microsoft for Startups

runner.execution-secrets-purge ​

Purge secret-bearing keys (environment, last_logs, inferred_failure_reason, log_next_page_token) from a runner execution's metadata. Targets a single execution or a runner group (optionally time-bounded). Org-scoped from the Bearer token, idempotent, and audited via an execution_secrets_purged group event.

Clear secret-bearing keys from runner execution metadata.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-runners
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant.
runner_execution_uuiduuidNo—UUID of a single RunnerExecution to purge, picked from the organization's (optionally group-scoped) list of executions. Mutually exclusive with runner_group_uuid.
runner_group_uuiduuidNo—UUID of a RunnerGroup whose executions should be purged in batch, picked from the organization's list of runner groups. Mutually exclusive with runner_execution_uuid.
created_afterstringNo—Batch mode only — ISO-8601 lower bound on RunnerExecution.created_at.
created_beforestringNo—Batch mode only — ISO-8601 upper bound on RunnerExecution.created_at.
limitintegerNo500Batch mode only — max rows examined in one run (default 500, ceiling 5000). Re-run to continue through a larger backlog.
dry_runbooleanNoFalseReport what would be purged without writing anything (no metadata change, no audit event).
reasonstringNo—Free-form justification recorded on the audit event.
actor_uuiduuidNo—UUID of the user or service actor who triggered this action, injected server-side from the authenticated request; used for audit/attribution only. Optional — omit for system or service-triggered actions with no human actor.

Output Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidNo—UUID of the RunnerGroup this action operates on, picked from the organization's list of runner groups; echoed on output alongside terminal/error payloads.
organization_uuiduuidNo—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. Echoed on output alongside terminal/error payloads.
runner_execution_uuiduuidNo—UUID of the RunnerExecution this action operates on, picked from the organization's (optionally group-scoped) list of executions; echoed on output alongside terminal/error payloads.
workflow_uuidstringNo—Engine workflow-run identifier (or, for GitHub-Actions-triggered flows, an external GitHub Actions run id) associated with this record; not a platform entity foreign key despite the name. No source is attached since there is no list/query workflow for an internal run id.
statusstringNo——
outcomestringNo——
initiated_atstringNo——
completed_atstringNo——
failed_atstringNo——
failure_reasonstringNo——
errorstringNo——
error_typestringNo——
actor_uuiduuidNo—UUID of the user or service actor who triggered this action, injected server-side from the authenticated request when available; used for audit/attribution only. Optional — omitted for system or service-triggered actions with no human actor.
reasonstringNo——
workflow_run_uuidstringNo—Engine-stamped correlation/run id for this DAG execution (ADR-015/E1 plumbing), written into state_data by action_start; not a foreign key to any business entity. No source is attached since there is no list/query workflow for an internal run id.
retry_countintegerNo——
retried_fromstringNo——
failed_stepjsonNo——
failed_layerjsonNo——
failed_at_statejsonNo——
compensation_triggerjsonNo——
comp_current_layerjsonNo——
comp_queuejsonNo——
comp_retry_countjsonNo——
purged_keyslistNo—Metadata key NAMES cleared across the batch (never their values).
purgeable_keyslistNo—The full set of key names this workflow is able to clear.
scanned_countintegerNo——
purged_countintegerNo——
purged_execution_uuidslistNo—UUIDs of the RunnerExecution rows actually modified.
purged_atstringNo——
truncatedbooleanNo—True when the batch hit limit; re-run to continue.
created_afterstringNo——
created_beforestringNo——
limitintegerNo——
dry_runbooleanNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "runner.execution-secrets-purge",
  "initial_data": {
    "organization_uuid": "value"
  }
}