Skip to content
Proud to collaborate with Microsoft for Startups

runner.grant_ar_service_agent_secret_access ​

Ensure the AR service agent has secretAccessor on the mirror secret

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-runners-gcp
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidYes—RunnerGroup UUID
organization_uuiduuidNo—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant.
workflow_run_idstringNo—Engine-stamped workflow run ID
workflow_run_uuidstringNo—Internal engine correlation/run identifier for this DAG execution (ADR-015/E1); not a reference to any business entity.
upstream_urlstringNo—Upstream registry URL (e.g. https://ghcr.io). Derived from runner_group.config.container_image when omitted.
upstream_hoststringNo—Upstream registry host only
cloud_connection_uuiduuidNo—UUID of the CloudConnection backing this runner group's Cloud Run backend, picked from the organization's connections, narrowed to GCP connections since this workflow only operates on Cloud Run runners. Optional here — coordinates are resolved by the validate step and forwarded by the DAG rather than supplied directly by the caller.
mirror_uuiduuidNo—CloudRunRegistryMirror UUID, resolved by the validate step and forwarded across subsequent DAG steps as an output-only echo. No data.*.list/get workflow exists for this entity anywhere in the platform, so no source picker is attached.
project_idstringNo—GCP project ID hosting the AR repo
project_numberstringNo—GCP numeric project number (for AR service agent)
regionstringNo—AR region
repository_idstringNo—Deterministic AR repo ID
secret_idstringNo—Deterministic Secret Manager secret ID
ar_service_agent_emailstringNo—AR service agent service account email
upstream_usernamestringNo—Upstream registry username (from ensure_secret)
password_secret_versionstringNo—Secret Manager version path (from ensure_secret)
secret_iam_granted_atstringNo—ISO timestamp from grant_iam step
provider_resource_idstringNo—AR repo resource name (from ensure_repository)
last_verified_atstringNo—ISO timestamp from verify step
completed_atstringNo—Inherited step completion timestamp
skipbooleanNo—Marker set by validate when no mirror is required
skippedstringNo—Name of step that honoured the skip marker

Output Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidYes—RunnerGroup UUID
organization_uuiduuidNo—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant.
workflow_run_idstringNo—Engine-stamped workflow run ID
workflow_run_uuidstringNo—Internal engine correlation/run identifier for this DAG execution (ADR-015/E1); not a reference to any business entity.
upstream_urlstringNo—Upstream registry URL (e.g. https://ghcr.io). Derived from runner_group.config.container_image when omitted.
upstream_hoststringNo—Upstream registry host only
cloud_connection_uuiduuidNo—UUID of the CloudConnection backing this runner group's Cloud Run backend, picked from the organization's connections, narrowed to GCP connections since this workflow only operates on Cloud Run runners. Optional here — coordinates are resolved by the validate step and forwarded by the DAG rather than supplied directly by the caller.
mirror_uuiduuidNo—CloudRunRegistryMirror UUID, resolved by the validate step and forwarded across subsequent DAG steps as an output-only echo. No data.*.list/get workflow exists for this entity anywhere in the platform, so no source picker is attached.
project_idstringNo—GCP project ID hosting the AR repo
project_numberstringNo—GCP numeric project number (for AR service agent)
regionstringNo—AR region
repository_idstringNo—Deterministic AR repo ID
secret_idstringNo—Deterministic Secret Manager secret ID
ar_service_agent_emailstringNo—AR service agent service account email
upstream_usernamestringNo—Upstream registry username (from ensure_secret)
password_secret_versionstringNo—Secret Manager version path (from ensure_secret)
secret_iam_granted_atstringNo—ISO timestamp from grant_iam step
provider_resource_idstringNo—AR repo resource name (from ensure_repository)
last_verified_atstringNo—ISO timestamp from verify step
completed_atstringNo—Inherited step completion timestamp
skipbooleanNo—Marker set by validate when no mirror is required
skippedstringNo—Name of step that honoured the skip marker
statusstringNo—Mirror status
failed_atstringNo—Step failure timestamp
failure_reasonstringNo—Populated only when the workflow ends in FAILED
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
initiatedYesNo—run—
runNoNo—complete—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
initiatedrunrun—
runcompletecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "runner.grant_ar_service_agent_secret_access",
  "initial_data": {
    "runner_group_uuid": "value"
  }
}