Skip to content
Proud to collaborate with Microsoft for Startups

runner.group-creation ​

Creates and provisions a runner group: persists the row from the supplied domain fields (or provisions an existing one when runner_group_uuid is given), then provisions all its infrastructure

Create AND provision a runner group: persist the row (if needed) → validate connections → per-backend cloud provision → flip to ACTIVE.

Overview ​

PropertyValue
Workflow typeDag
LibraryApp-runners
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidNo—UUID of an EXISTING RunnerGroup to provision. Omit to create a brand-new group from the fields below (name, backend_type, cloud_connection_uuid, …): this workflow persists the row itself and then provisions it. Supply it only to (re)provision a group that already exists — e.g. after runner.group-creation-abort.
organization_uuiduuidYes—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant.
namestringYes—Human-readable runner group name, unique per organization (and among non-deleted groups). Used to label the group and derive cloud resource names.
backend_typestringYes—Compute backend that runs this group's runners. One of: devkit, fargate, ec2_auto_scaling, ec2_vm, gce, cloud_run, kubernetes, eks, azure_container_apps_job, azure_vm, azure_vmss, do_app_job, do_droplet, mgc_vm. Determines which cloud connection and config keys are required — call data.runner.list-provider-config-specs for the config keys per backend.
purposestringYes—What the runners are for. One of: github_actions, gitlab_runner, generic, agent. Use 'agent' to host Orkestia agent sessions; 'generic' for plain container jobs with no CI integration.
integration_typestringYes—CI system this group registers runners with. One of: github, gitlab, none. 'github' requires github_installation_uuid; 'gitlab' requires gitlab_connection_uuid (+ project/group target); 'none' registers no external CI runner.
runner_scopestringYes—Scope the runners are registered at. One of: organization, repository. 'repository' (GitHub only) requires github_repository_uuid.
cloud_connection_uuiduuidNo—UUID of the CloudConnection backing provider-backed runner groups. Required for cloud backends; omit for backend_type=devkit.
network_profile_uuiduuidNo—UUID of the NetworkProfile bound to this runner group, picked from the organization's network profiles. Optional — omit when absent.
registry_account_uuiduuidNo—UUID of the container registry account this runner group resolves images against, picked from the organization's registry accounts. Optional — falls back to default/unauthenticated image resolution when absent.
image_pull_cloud_connection_uuiduuidNo—UUID of the CloudConnection used to authenticate image pulls for this runner group, picked from the organization's connections. Optional — falls back to cloud_connection_uuid when absent.
github_installation_uuiduuidNo—UUID of the GitHub App installation bound to this runner group's GitHub integration. No list/query workflow exists in the platform today (data.github.installation.list has not been built), so this value must be supplied directly by the caller; omit when absent.
github_repository_uuiduuidNo—UUID of the GitHub repository this runner group is scoped to, picked from repositories under the organization. Optional — omit when absent (only set for repository-scoped groups).
gitlab_connection_uuiduuidNo—UUID of the GitLab CloudConnection bound to this runner group, picked from the organization's GitLab connections. Optional — omit when absent (only set for GitLab-integrated groups).
gitlab_project_uuiduuidNo—UUID of the GitLab project this runner group is scoped to. No list/query workflow exists in the platform today (data.gitlab.project.list has not been built), so this value must be supplied directly by the caller; omit when absent.
gitlab_target_kindstringNo——
gitlab_group_pathstringNo——
regionstringNo—Cloud region the runners are provisioned in (e.g. 'us-east-1' for AWS). Required for all cloud backends (aws/gcp/azure/digitalocean/mgc); omit only for bring-your-own kubernetes.
desired_countintegerNo1—
min_countintegerNo0—
max_countintegerNo10—
descriptionstringNo——
runner_labelslistNo——
configdictNo—Backend-specific settings (e.g. ecs_cluster_name for Fargate, machine_type for GCE, container_image). Required keys vary by backend_type — call data.runner.list-provider-config-specs to get the exact keys before creating.
coding_runtime_enabledbooleanNo—Enable the software-development-v1 runtime profile for this agent runner group. Requires a customer storage connection; runner.group-creation provisions and binds the private artifact bucket through the Storage workflow.
coding_artifact_storage_connection_uuiduuidNo—Customer CloudConnection used by the Storage workflow to provision private coding-artifact storage.
coding_artifact_retention_daysintegerNo—Recovery retention for noncurrent artifact versions, between 7 and 90 days.
coding_artifact_capacity_bytesintegerNo—Required hard live-byte ceiling for the customer-owned coding-artifact bucket. Valid range: 512 MiB to 1 TiB.
coding_artifact_storage_usd_per_gb_monthstringNo—Customer storage price in USD per decimal GB-month, passed only to the Storage-owned provisioning workflow.
coding_artifact_storage_pricing_revisionstringNo—Immutable revision identifier for the supplied storage price.
auth_typestringNo——
actor_uuiduuidNo—UUID of the user or service actor who triggered this action, injected server-side from the authenticated request; used for audit/attribution only. Optional — omit for system or service-triggered actions with no human actor.

Output Schema ​

FieldTypeRequiredDefaultDescription
runner_group_uuiduuidNo—UUID of the RunnerGroup this action operates on, picked from the organization's list of runner groups; echoed on output alongside terminal/error payloads.
organization_uuiduuidNo—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. Echoed on output alongside terminal/error payloads.
runner_execution_uuiduuidNo—UUID of the RunnerExecution this action operates on, picked from the organization's (optionally group-scoped) list of executions; echoed on output alongside terminal/error payloads.
workflow_uuidstringNo—Engine workflow-run identifier (or, for GitHub-Actions-triggered flows, an external GitHub Actions run id) associated with this record; not a platform entity foreign key despite the name. No source is attached since there is no list/query workflow for an internal run id.
statusstringNo——
outcomestringNo——
initiated_atstringNo——
completed_atstringNo——
failed_atstringNo——
failure_reasonstringNo——
errorstringNo——
error_typestringNo——
actor_uuiduuidNo—UUID of the user or service actor who triggered this action, injected server-side from the authenticated request when available; used for audit/attribution only. Optional — omitted for system or service-triggered actions with no human actor.
reasonstringNo——
workflow_run_uuidstringNo—Engine-stamped correlation/run id for this DAG execution (ADR-015/E1 plumbing), written into state_data by action_start; not a foreign key to any business entity. No source is attached since there is no list/query workflow for an internal run id.
retry_countintegerNo——
retried_fromstringNo——
failed_stepjsonNo——
failed_layerjsonNo——
failed_at_statejsonNo——
compensation_triggerjsonNo——
comp_current_layerjsonNo——
comp_queuejsonNo——
comp_retry_countjsonNo——
backend_typestringNo——
integration_typestringNo——
runner_group_namestringNo——
hosted_coding_pool_refresh_requiredbooleanNo——
registry_account_uuiduuidNo—UUID of the container registry account this runner group resolves images against, picked from the organization's registry accounts. Omitted when the group uses default/unauthenticated image resolution.
activated_atstringNo——
created_atstringNo——
namestringNo—Human-readable runner group name, unique per organization (and among non-deleted groups). Used to label the group and derive cloud resource names.
purposestringNo—What the runners are for. One of: github_actions, gitlab_runner, generic, agent. Use 'agent' to host Orkestia agent sessions; 'generic' for plain container jobs with no CI integration.
runner_scopestringNo—Scope the runners are registered at. One of: organization, repository. 'repository' (GitHub only) requires github_repository_uuid.
cloud_connection_uuiduuidNo—UUID of the CloudConnection backing provider-backed runner groups. Required for cloud backends; omit for backend_type=devkit.
network_profile_uuiduuidNo—UUID of the NetworkProfile bound to this runner group, picked from the organization's network profiles. Optional — omit when absent.
image_pull_cloud_connection_uuiduuidNo—UUID of the CloudConnection used to authenticate image pulls for this runner group, picked from the organization's connections. Optional — falls back to cloud_connection_uuid when absent.
github_installation_uuiduuidNo—UUID of the GitHub App installation bound to this runner group's GitHub integration. No list/query workflow exists in the platform today (data.github.installation.list has not been built), so this value must be supplied directly by the caller; omit when absent.
github_repository_uuiduuidNo—UUID of the GitHub repository this runner group is scoped to, picked from repositories under the organization. Optional — omit when absent (only set for repository-scoped groups).
gitlab_connection_uuiduuidNo—UUID of the GitLab CloudConnection bound to this runner group, picked from the organization's GitLab connections. Optional — omit when absent (only set for GitLab-integrated groups).
gitlab_project_uuiduuidNo—UUID of the GitLab project this runner group is scoped to. No list/query workflow exists in the platform today (data.gitlab.project.list has not been built), so this value must be supplied directly by the caller; omit when absent.
gitlab_target_kindstringNo——
gitlab_group_pathstringNo——
regionstringNo—Cloud region the runners are provisioned in (e.g. 'us-east-1' for AWS). Required for all cloud backends (aws/gcp/azure/digitalocean/mgc); omit only for bring-your-own kubernetes.
desired_countintegerNo1—
min_countintegerNo0—
max_countintegerNo10—
descriptionstringNo——
runner_labelslistNo——
configdictNo—Backend-specific settings (e.g. ecs_cluster_name for Fargate, machine_type for GCE, container_image). Required keys vary by backend_type — call data.runner.list-provider-config-specs to get the exact keys before creating.
coding_runtime_enabledbooleanNo—Enable the software-development-v1 runtime profile for this agent runner group. Requires a customer storage connection; runner.group-creation provisions and binds the private artifact bucket through the Storage workflow.
coding_artifact_storage_connection_uuiduuidNo—Customer CloudConnection used by the Storage workflow to provision private coding-artifact storage.
coding_artifact_retention_daysintegerNo—Recovery retention for noncurrent artifact versions, between 7 and 90 days.
coding_artifact_capacity_bytesintegerNo—Required hard live-byte ceiling for the customer-owned coding-artifact bucket. Valid range: 512 MiB to 1 TiB.
coding_artifact_storage_usd_per_gb_monthstringNo—Customer storage price in USD per decimal GB-month, passed only to the Storage-owned provisioning workflow.
coding_artifact_storage_pricing_revisionstringNo—Immutable revision identifier for the supplied storage price.
auth_typestringNo——
preparejsonNo——
ensure_coding_artifact_storagejsonNo——
env_provision_fargatejsonNo——
env_provision_ec2jsonNo——
env_provision_gcejsonNo——
env_provision_cloud_runjsonNo——
env_provision_kubernetesjsonNo——
env_provision_eksjsonNo——
env_provision_azure_container_appsjsonNo——
env_provision_do_app_jobjsonNo——
env_provision_ec2_vmjsonNo——
reconcile_environment_builder_configjsonNo——
refresh_hosted_coding_pooljsonNo——
finalize_group_creationjsonNo——

DAG Layers ​

#LayerStepsCompensation
1preparerunner.group-creation.prepare—
2provision_coding_storagestorage.coding-artifact-bucket.ensure—
3provision_environmentrunner.environment-provision, runner.environment-provision-ec2, runner.environment-provision-gcp, runner.environment-provision-cloud-run, runner.environment-provision-kubernetes, runner.environment-provision-kubernetes, runner.environment-provision-azure-container-apps, runner.environment-provision-do-app-job, runner.environment-provision-ec2-vm—
4reconcile_environment_builderrunner.environment-builder-config-reconcile-kubernetes—
5refresh_hosted_coding_poolrunner.pool-rotate—
6finalizerunner.group-creation.finalize—

Execution Flow ​

Sub-workflows ​

Sub-workflowStep name
runner.group-creation.prepareprepare
storage.coding-artifact-bucket.ensureensure_coding_artifact_storage
runner.environment-provisionenv_provision_fargate
runner.environment-provision-ec2env_provision_ec2
runner.environment-provision-gcpenv_provision_gce
runner.environment-provision-cloud-runenv_provision_cloud_run
runner.environment-provision-kubernetesenv_provision_kubernetes
runner.environment-provision-azure-container-appsenv_provision_azure_container_apps
runner.environment-provision-do-app-jobenv_provision_do_app_job
runner.environment-provision-ec2-vmenv_provision_ec2_vm
runner.environment-builder-config-reconcile-kubernetesreconcile_environment_builder_config
runner.pool-rotaterefresh_hosted_coding_pool
runner.group-creation.finalizefinalize_group_creation

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "runner.group-creation",
  "initial_data": {
    "organization_uuid": "value",
    "name": "value",
    "backend_type": "value",
    "purpose": "value"
  }
}