runner.execution-secrets-purge
Purge secret-bearing keys (environment, last_logs, inferred_failure_reason, log_next_page_token) from a runner execution's metadata. Targets a single execution or a runner group (optionally time-bounded). Org-scoped from the Bearer token, idempotent, and audited via an execution_secrets_purged group event.
Clear secret-bearing keys from runner execution metadata.
Overview
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-runners |
| Version | 1.0 |
Input Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
runner_execution_uuid | uuid | No | — | UUID of a single RunnerExecution to purge, picked from the organization's (optionally group-scoped) list of executions. Mutually exclusive with runner_group_uuid. |
runner_group_uuid | uuid | No | — | UUID of a RunnerGroup whose executions should be purged in batch, picked from the organization's list of runner groups. Mutually exclusive with runner_execution_uuid. |
created_after | string | No | — | Batch mode only — ISO-8601 lower bound on RunnerExecution.created_at. |
created_before | string | No | — | Batch mode only — ISO-8601 upper bound on RunnerExecution.created_at. |
limit | integer | No | 500 | Batch mode only — max rows examined in one run (default 500, ceiling 5000). Re-run to continue through a larger backlog. |
dry_run | boolean | No | False | Report what would be purged without writing anything (no metadata change, no audit event). |
reason | string | No | — | Free-form justification recorded on the audit event. |
actor_uuid | uuid | No | — | UUID of the user or service actor who triggered this action, injected server-side from the authenticated request; used for audit/attribution only. Optional — omit for system or service-triggered actions with no human actor. |
Output Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | No | — | UUID of the RunnerGroup this action operates on, picked from the organization's list of runner groups; echoed on output alongside terminal/error payloads. |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. Echoed on output alongside terminal/error payloads. |
runner_execution_uuid | uuid | No | — | UUID of the RunnerExecution this action operates on, picked from the organization's (optionally group-scoped) list of executions; echoed on output alongside terminal/error payloads. |
workflow_uuid | string | No | — | Engine workflow-run identifier (or, for GitHub-Actions-triggered flows, an external GitHub Actions run id) associated with this record; not a platform entity foreign key despite the name. No source is attached since there is no list/query workflow for an internal run id. |
status | string | No | — | — |
outcome | string | No | — | — |
initiated_at | string | No | — | — |
completed_at | string | No | — | — |
failed_at | string | No | — | — |
failure_reason | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
actor_uuid | uuid | No | — | UUID of the user or service actor who triggered this action, injected server-side from the authenticated request when available; used for audit/attribution only. Optional — omitted for system or service-triggered actions with no human actor. |
reason | string | No | — | — |
workflow_run_uuid | string | No | — | Engine-stamped correlation/run id for this DAG execution (ADR-015/E1 plumbing), written into state_data by action_start; not a foreign key to any business entity. No source is attached since there is no list/query workflow for an internal run id. |
retry_count | integer | No | — | — |
retried_from | string | No | — | — |
failed_step | json | No | — | — |
failed_layer | json | No | — | — |
failed_at_state | json | No | — | — |
compensation_trigger | json | No | — | — |
comp_current_layer | json | No | — | — |
comp_queue | json | No | — | — |
comp_retry_count | json | No | — | — |
purged_keys | list | No | — | Metadata key NAMES cleared across the batch (never their values). |
purgeable_keys | list | No | — | The full set of key names this workflow is able to clear. |
scanned_count | integer | No | — | — |
purged_count | integer | No | — | — |
purged_execution_uuids | list | No | — | UUIDs of the RunnerExecution rows actually modified. |
purged_at | string | No | — | — |
truncated | boolean | No | — | True when the batch hit limit; re-run to continue. |
created_after | string | No | — | — |
created_before | string | No | — | — |
limit | integer | No | — | — |
dry_run | boolean | No | — | — |
States
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram
Transitions
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "runner.execution-secrets-purge",
"initial_data": {
"organization_uuid": "value"
}
}