runner.validate_cloud_run_registry_mirror ​
Resolve mirror coordinates and prepare the mirror row
Overview ​
| Property | Value |
|---|---|
| Workflow type | Linear |
| Library | App-runners-gcp |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | Yes | — | RunnerGroup UUID |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
workflow_run_id | string | No | — | Engine-stamped workflow run ID |
workflow_run_uuid | string | No | — | Internal engine correlation/run identifier for this DAG execution (ADR-015/E1); not a reference to any business entity. |
upstream_url | string | No | — | Upstream registry URL (e.g. https://ghcr.io). Derived from runner_group.config.container_image when omitted. |
upstream_host | string | No | — | Upstream registry host only |
cloud_connection_uuid | uuid | No | — | UUID of the CloudConnection backing this runner group's Cloud Run backend, picked from the organization's connections, narrowed to GCP connections since this workflow only operates on Cloud Run runners. Optional here — coordinates are resolved by the validate step and forwarded by the DAG rather than supplied directly by the caller. |
mirror_uuid | uuid | No | — | CloudRunRegistryMirror UUID, resolved by the validate step and forwarded across subsequent DAG steps as an output-only echo. No data.*.list/get workflow exists for this entity anywhere in the platform, so no source picker is attached. |
project_id | string | No | — | GCP project ID hosting the AR repo |
project_number | string | No | — | GCP numeric project number (for AR service agent) |
region | string | No | — | AR region |
repository_id | string | No | — | Deterministic AR repo ID |
secret_id | string | No | — | Deterministic Secret Manager secret ID |
ar_service_agent_email | string | No | — | AR service agent service account email |
upstream_username | string | No | — | Upstream registry username (from ensure_secret) |
password_secret_version | string | No | — | Secret Manager version path (from ensure_secret) |
secret_iam_granted_at | string | No | — | ISO timestamp from grant_iam step |
provider_resource_id | string | No | — | AR repo resource name (from ensure_repository) |
last_verified_at | string | No | — | ISO timestamp from verify step |
completed_at | string | No | — | Inherited step completion timestamp |
skip | boolean | No | — | Marker set by validate when no mirror is required |
skipped | string | No | — | Name of step that honoured the skip marker |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
runner_group_uuid | uuid | Yes | — | RunnerGroup UUID |
organization_uuid | uuid | No | — | UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant. |
workflow_run_id | string | No | — | Engine-stamped workflow run ID |
workflow_run_uuid | string | No | — | Internal engine correlation/run identifier for this DAG execution (ADR-015/E1); not a reference to any business entity. |
upstream_url | string | No | — | Upstream registry URL (e.g. https://ghcr.io). Derived from runner_group.config.container_image when omitted. |
upstream_host | string | No | — | Upstream registry host only |
cloud_connection_uuid | uuid | No | — | UUID of the CloudConnection backing this runner group's Cloud Run backend, picked from the organization's connections, narrowed to GCP connections since this workflow only operates on Cloud Run runners. Optional here — coordinates are resolved by the validate step and forwarded by the DAG rather than supplied directly by the caller. |
mirror_uuid | uuid | No | — | CloudRunRegistryMirror UUID, resolved by the validate step and forwarded across subsequent DAG steps as an output-only echo. No data.*.list/get workflow exists for this entity anywhere in the platform, so no source picker is attached. |
project_id | string | No | — | GCP project ID hosting the AR repo |
project_number | string | No | — | GCP numeric project number (for AR service agent) |
region | string | No | — | AR region |
repository_id | string | No | — | Deterministic AR repo ID |
secret_id | string | No | — | Deterministic Secret Manager secret ID |
ar_service_agent_email | string | No | — | AR service agent service account email |
upstream_username | string | No | — | Upstream registry username (from ensure_secret) |
password_secret_version | string | No | — | Secret Manager version path (from ensure_secret) |
secret_iam_granted_at | string | No | — | ISO timestamp from grant_iam step |
provider_resource_id | string | No | — | AR repo resource name (from ensure_repository) |
last_verified_at | string | No | — | ISO timestamp from verify step |
completed_at | string | No | — | Inherited step completion timestamp |
skip | boolean | No | — | Marker set by validate when no mirror is required |
skipped | string | No | — | Name of step that honoured the skip marker |
status | string | No | — | Mirror status |
failed_at | string | No | — | Step failure timestamp |
failure_reason | string | No | — | Populated only when the workflow ends in FAILED |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
initiated | Yes | No | — | run | — |
run | No | No | — | complete | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
initiated | run | run | — |
run | complete | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "runner.validate_cloud_run_registry_mirror",
"initial_data": {
"runner_group_uuid": "value"
}
}