Vocabulary
The canonical enumerations shared across the API, worker, scheduler, and UI, defined in packages/core/enums.py. Statuses, phases, node types, outcomes, and event kinds used anywhere in the platform come from this vocabulary.
EventKind
Types of events emitted during workflow execution.
| Name | Value |
|---|---|
STAGE_CHANGE | stage_change |
LOG | log |
ERROR | error |
NOTIFICATION | notification |
PROGRESS | progress |
GRAPH_FORK_SPLIT | graph.fork_split |
GRAPH_JOIN_ARRIVAL | graph.join_arrival |
GRAPH_JOIN_COMPLETE | graph.join_complete |
Transport
Device communication transports.
| Name | Value |
|---|---|
SSH | ssh |
NETCONF | netconf |
GNMI | gnmi |
ArtifactKind
Types of artifacts captured during evidence collection.
| Name | Value |
|---|---|
CLI_OUTPUT | cli_output |
FACTS_JSON | facts_json |
TRANSPORT_META | transport_meta |
STEP_RESULT | step_result |
POLL_RESULT | poll_result |
CONNECTIVITY_MONITOR | connectivity_monitor |
COMPARISON_RESULT | comparison_result |
ASSERTION_RESULT | assertion_result |
CONTAINER_OUTPUT | container_output |
DOWNLOADABLE_FILE | downloadable_file |
EGRESS_REPORT | egress_report |
StepStatus
Execution status of a step run.
| Name | Value |
|---|---|
PENDING | PENDING |
RUNNING | RUNNING |
SUCCESS | SUCCESS |
FAILED | FAILED |
SKIPPED | SKIPPED |
CANCELLED | CANCELLED |
RunStatus
Execution status of a flow run.
| Name | Value |
|---|---|
PENDING | PENDING |
RUNNING | RUNNING |
PAUSED | PAUSED |
WAITING_APPROVAL | WAITING_APPROVAL |
SUCCESS | SUCCESS |
FAILED | FAILED |
CANCELLED | CANCELLED |
RunTriggerSource
What started a flow run.
The five ways a run can begin, named once so admission checks can switch on them instead of sniffing created_by. manual is a person (or a script holding their token) calling POST /runs; run_now is a person pressing "Run now" on a schedule, which is still the schedule's own trigger and so stays distinct from manual; flow is a nested child run created by a parent's flow.run step.
Recorded on an audit entry as its trigger_source detail (see AuditAction), and read by apps/api/services/manual_run_policy.py to decide whether a flow that refuses hand-started runs admits this one.
| Name | Value |
|---|---|
MANUAL | manual |
RUN_NOW | run_now |
SCHEDULE | schedule |
WEBHOOK | webhook |
FLOW | flow |
ExecutionAffinity
Worker-placement preference for a flow run or an individual step.
Controls which Temporal task queue a step's execute activity is dispatched to, and therefore which worker host runs it.
distributed: any worker may pick up the step (default; today's behavior). Steps cannot use the per-run shared workspace because they may run on a different host.shared: allsharedsteps of a run are pinned to one randomly chosen worker and share a per-run workspace volume mounted at/shared.explicit: pin to a named worker (seeexecution_worker). Reserved for the multi-host future; today validated against the single worker.
| Name | Value |
|---|---|
DISTRIBUTED | distributed |
SHARED | shared |
EXPLICIT | explicit |
MaintenanceJobStatus
Persisted execution status for internal maintenance jobs.
| Name | Value |
|---|---|
RUNNING | RUNNING |
SUCCESS | SUCCESS |
FAILED | FAILED |
MaintenanceJobHealth
Derived health state for internal maintenance jobs.
| Name | Value |
|---|---|
HEALTHY | healthy |
FAILED | failed |
OVERDUE | overdue |
RUNNING | running |
STALE_RUNNING | stale_running |
DISABLED | disabled |
NEVER_RUN | never_run |
Capability
Inventory provider capabilities.
| Name | Value |
|---|---|
READ | read |
QUERY | query |
WRITE | write |
WEBHOOK | webhook |
DISCOVER | discover |
DELTA | delta |
ResourceType
Inventory provider resource families.
| Name | Value |
|---|---|
DEVICE | device |
SITE | site |
IP_PREFIX | ip_prefix |
IP_ADDRESS | ip_address |
VLAN | vlan |
CONTACT | contact |
ProviderErrorCode
Stable provider error envelope codes.
| Name | Value |
|---|---|
TIMEOUT | timeout |
AUTH_FAILED | auth_failed |
TLS_FAILED | tls_failed |
NOT_FOUND | not_found |
PAGINATION_FAILED | pagination_failed |
MALFORMED_QUERY | malformed_query |
SCHEMA_VALIDATION_FAILED | schema_validation_failed |
UNAVAILABLE | unavailable |
MaintenanceState
Local maintenance marker for inventory identity rows.
| Name | Value |
|---|---|
ACTIVE | active |
MAINTENANCE | maintenance |
DISABLED | disabled |
EdgeType
Type of edge in a flow graph.
execution: Normal execution edge - routes tokens and counts toward join inputs. termination: Monitor termination edge - when the target join fires, attached monitors are stopped. Does not route tokens or count as join input.
| Name | Value |
|---|---|
EXECUTION | execution |
TERMINATION | termination |
MonitorScheduleMode
How a monitor determines when to stop.
COUNT: Run exactly N ticks, then complete and route token to successors. Monitor self-terminates after count is reached.
DURATION: Run for duration_s total, then complete and route token to successors. Monitor self-terminates after duration elapses.
UNTIL_JOIN: Fire-and-forget background monitor. The join node handles termination when all (or any, depending on join mode) regular branches have arrived. Does NOT route token - join does not count this as an incoming branch. Monitor is stopped by the join after it processes its regular inputs.
Note: All monitors are automatically stopped when the run completes (success/failure) via stop_run_monitors activity, so explicit termination is only needed for mid-run control.
| Name | Value |
|---|---|
COUNT | count |
DURATION | duration |
UNTIL_JOIN | until_join |
MonitorTargetType
How a monitor target is specified.
| Name | Value |
|---|---|
ROLE | role |
IP | ip |
MonitorAddressKind
Which address to use when resolving a role-based target.
| Name | Value |
|---|---|
MGMT | mgmt |
PRIMARY | primary |
LOOPBACK | loopback |
CUSTOM | custom |
MonitorAddressFamily
IP address family preference.
| Name | Value |
|---|---|
AUTO | auto |
IPV4 | ipv4 |
IPV6 | ipv6 |
InterfaceNodeKind
Node kinds in the Flow Interface Builder authoring graph.
| Name | Value |
|---|---|
SECTION | section |
FIELD | field |
CONDITION | condition |
OPTION_SOURCE | option_source |
VALIDATION | validation |
NOTE | note |
InterfaceEdgeSemanticType
Semantic type of an edge in the Flow Interface Builder graph.
Only relation types the compiler actually implements are listed; a new type must land together with its compiler + runtime support. Stored graphs containing retired/unknown types still load — the compiler skips those relations and reports an UNSUPPORTED_EDGE_RELATION warning.
options_filter: Source field value filters the target field's options. visible_when: Source field controls whether target field is shown. enabled_when: Source field controls whether target field is editable. required_when: Source field controls whether target field is required.
| Name | Value |
|---|---|
OPTIONS_FILTER | options_filter |
VISIBLE_WHEN | visible_when |
ENABLED_WHEN | enabled_when |
REQUIRED_WHEN | required_when |
InterfaceProblemSeverity
Severity of a validation problem produced by the interface graph compiler.
| Name | Value |
|---|---|
ERROR | error |
WARNING | warning |
INFO | info |
MonitorCheckId
Built-in connectivity check types.
| Name | Value |
|---|---|
ICMP_PING | icmp_ping |
TCP_CONNECT | tcp_connect |
DNS_RESOLVE | dns_resolve |
HTTP_HEALTH | http_health |
TLS_HANDSHAKE | tls_handshake |
SSH_BANNER | ssh_banner |
MonitorStatus
Status of a monitor instance.
| Name | Value |
|---|---|
PENDING | pending |
RUNNING | running |
PAUSED | paused |
STOPPED | stopped |
COMPLETED | completed |
FAILED | failed |
ApprovalStatus
Status of an approval request.
| Name | Value |
|---|---|
PENDING | PENDING |
APPROVED | APPROVED |
REJECTED | REJECTED |
EXPIRED | EXPIRED |
CANCELLED | CANCELLED |
ScheduleType
Types of schedule cadence.
| Name | Value |
|---|---|
ONE_TIME | one_time |
RECURRING | recurring |
ScheduleStatus
Lifecycle status for schedules.
| Name | Value |
|---|---|
ACTIVE | active |
DISABLED | disabled |
COMPLETED | completed |
FlowGraphNodeType
Type of node in a flow graph.
| Name | Value |
|---|---|
START | start |
STEP | step |
APPROVAL | approval |
PAUSE | pause |
TERMINAL | terminal |
FORK | fork |
JOIN | join |
GROUP | group |
BRANCH | branch |
LOOP | loop |
LOOP_END | loop_end |
SET_VARS | set_vars |
BranchMode
How a branch node selects its outgoing case.
RULES: Ordered per-case boolean conditions; first true case wins (if/elif). VALUE: One expression evaluated once, compared against per-case values (switch).
| Name | Value |
|---|---|
RULES | rules |
VALUE | value |
LoopMode
How a loop node decides whether to run another iteration.
WHILE: Check the condition before each iteration (0..N runs). UNTIL: Run the body, then check the condition (do-while, 1..N runs). COUNT: Run a fixed number of iterations. FOR_EACH: Iterate over the items produced by an expression.
| Name | Value |
|---|---|
WHILE | while |
UNTIL | until |
COUNT | count |
FOR_EACH | for_each |
LoopBodyFailurePolicy
What a loop does when a body step fails without a wired failure edge.
FAIL: Fail the whole run (default; matches non-loop behavior). BREAK: Exit the loop via its 'done' outcome (reserved; rejected at commit). CONTINUE: Skip to the next iteration (reserved; rejected at commit).
Commit validation accepts only FAIL; BREAK and CONTINUE are reserved for forward compatibility and rejected.
| Name | Value |
|---|---|
FAIL | fail |
BREAK | break |
CONTINUE | continue |
ParallelIterationFailurePolicy
What a parallel loop does when one iteration fails.
DRAIN: Stop dispatching new iterations, let in-flight ones finish, then fail the loop (default). CANCEL: Cancel the in-flight iterations and fail the loop immediately. CONTINUE: Run every remaining iteration, then fail the loop reporting all failed iterations.
Only meaningful when max_parallel_iterations > 1; sequential loops keep their existing failure behavior.
| Name | Value |
|---|---|
DRAIN | drain |
CANCEL | cancel |
CONTINUE | continue |
JoinMode
How a join node waits for incoming branches.
ALL: Wait for all incoming branches to complete ANY: Continue when any single branch completes successfully
| Name | Value |
|---|---|
ALL | all |
ANY | any |
JoinFailurePolicy
How a join node handles failed branches.
PROPAGATE: If any branch fails, the join fails after all complete FAIL_FAST: Fail immediately when any branch fails IGNORE_FAILURES: Continue if at least one branch succeeds (with ANY mode)
| Name | Value |
|---|---|
PROPAGATE | propagate |
FAIL_FAST | fail_fast |
IGNORE_FAILURES | ignore_failures |
JoinCancelPolicy
What to do with remaining branches when join condition is met.
CANCEL_OTHERS: Cancel remaining branches when condition met (useful with ANY) WAIT: Wait for all branches to complete regardless
| Name | Value |
|---|---|
CANCEL_OTHERS | cancel_others |
WAIT | wait |
FlowGraphOutcome
Canonical outcomes for graph node execution.
These are the standard outcomes that nodes produce. Edges attach to outcomes via source_outcome.
| Name | Value |
|---|---|
START | start |
SUCCESS | success |
FAILURE | failure |
CANCELLED | cancelled |
APPROVED | approved |
REJECTED | rejected |
EXPIRED | expired |
FORK | fork |
JOINED | joined |
JOIN_FAILED | join_failed |
ELSE | else |
ERROR | error |
ITERATE | iterate |
DONE | done |
MAX_ITERATIONS | max_iterations |
NotificationDestinationType
Types of notification destinations.
EMAIL: Send via SMTP SHOUTRRR: Use Shoutrrr CLI for arbitrary services (Discord, Slack, etc.) OUTGOING_WEBHOOK: Send HTTP requests to arbitrary endpoints
| Name | Value |
|---|---|
EMAIL | email |
SHOUTRRR | shoutrrr |
OUTGOING_WEBHOOK | outgoing_webhook |
NotificationEvent
Events that can trigger notifications.
Run lifecycle events and approval events.
| Name | Value |
|---|---|
RUN_STARTED | run.started |
RUN_PAUSED | run.paused |
RUN_RESUMED | run.resumed |
RUN_CANCELLED | run.cancelled |
RUN_FAILED | run.failed |
RUN_COMPLETED | run.completed |
APPROVAL_REQUESTED | approval.requested |
APPROVAL_APPROVED | approval.approved |
APPROVAL_REJECTED | approval.rejected |
APPROVAL_EXPIRED | approval.expired |
WebhookAuthMode
Authentication mode for inbound webhook verification.
| Name | Value |
|---|---|
HMAC_SHA256 | hmac_sha256 |
BEARER | bearer |
WebhookTargetType
Concrete target type linked to a webhook endpoint.
| Name | Value |
|---|---|
FLOW | flow |
SyncMode
Repository sync mode.
- SYNCED: Repository is kept in sync with upstream and changes are applied.
- READONLY: Repository content is available but cannot be mutated via the API.
- DETACHED: Repository is tracked but not actively synced.
| Name | Value |
|---|---|
SYNCED | synced |
READONLY | readonly |
DETACHED | detached |
ConflictPolicy
Policy to resolve conflicts when syncing remote changes.
- REJECT_DIRTY: Reject operations if local changes would be overwritten.
- OVERWRITE: Overwrite local changes with remote content.
- SKIP: Skip conflicting flows without applying changes.
- FORCE: Overwrite local changes with remote (force).
| Name | Value |
|---|---|
REJECT_DIRTY | reject_dirty |
OVERWRITE | overwrite |
SKIP | skip |
FORCE | force |
PlatformSyncMode
Authority mode for platform sync operations.
| Name | Value |
|---|---|
BACKUP | backup |
MIRROR | mirror |
BIDIRECTIONAL | bidirectional |
PlatformSyncOperation
Platform sync operation kind.
| Name | Value |
|---|---|
EXPORT | export |
PLAN | plan |
APPLY | apply |
PlatformSyncTriggerSource
How a platform sync run was triggered.
| Name | Value |
|---|---|
MANUAL | manual |
SCHEDULE | schedule |
PlatformSyncRunStatus
Lifecycle status for platform sync runs.
| Name | Value |
|---|---|
RUNNING | running |
SUCCESS | success |
NOOP | noop |
FAILED | failed |
CONFLICT | conflict |
BLOCKED | blocked |
PlatformSyncChangeKind
Change type detected by platform sync planning.
| Name | Value |
|---|---|
CREATE | create |
UPDATE | update |
DELETE | delete |
NOOP | noop |
CONFLICT | conflict |
PlatformSyncResourceFamily
Supported resource families for platform sync bundles.
| Name | Value |
|---|---|
FLOW | flow |
SITE | site |
DEVICE | device |
SECRET | secret |
SECRET_BACKEND | secret_backend |
VARIABLE | variable |
SCHEDULE | schedule |
NOTIFICATION_DESTINATION | notification_destination |
FLOW_NOTIFICATION_SUBSCRIPTION | flow_notification_subscription |
WEBHOOK_ENDPOINT | webhook_endpoint |
FILE_REPOSITORY | file_repository |
GIT_REPOSITORY | git_repository |
REGISTRY_CREDENTIAL | registry_credential |
PERMISSION_OVERRIDE | permission_override |
PERMISSION_ACTION_OVERRIDE | permission_action_override |
INVENTORY_PROVIDER_CONFIG | inventory_provider_config |
PLATFORM_SYNC_PROFILE | platform_sync_profile |
PlatformSyncDestructivePolicy
Policy for destructive apply behavior.
| Name | Value |
|---|---|
BLOCK | block |
ALLOW_WITH_CONFIRMATION | allow_with_confirmation |
ALLOW_AUTOMATED | allow_automated |
PlatformSyncConflictResolution
Conflict resolution preference for bidirectional sync.
| Name | Value |
|---|---|
PREFER_GIT | prefer_git |
PREFER_PLATFORM | prefer_platform |
MANUAL_EDIT | manual_edit |
ConfigExchangeActorKind
Actor kind for configuration exchange operations.
| Name | Value |
|---|---|
USER | user |
SERVICE | service |
ConfigExchangeLayout
Layout options for configuration exchange payloads.
| Name | Value |
|---|---|
SINGLE_YAML | single_yaml |
EXPLODED_PLATFORM | exploded_platform |
FLOW_YAML | flow_yaml |
ConfigExchangeOperation
Operation types for configuration exchange.
| Name | Value |
|---|---|
EXPORT | export |
IMPORT | import |
PLAN | plan |
APPLY | apply |
ConfigExchangeScope
Scope for configuration exchange operations.
| Name | Value |
|---|---|
PLATFORM | platform |
FLOW | flow |
ConfigExchangeTransport
Transport options for configuration exchange payload delivery.
| Name | Value |
|---|---|
DOWNLOAD | download |
UPLOAD | upload |
INLINE | inline |
GIT | git |
ConfigExchangePlanStatus
Lifecycle status for configuration exchange import plans.
| Name | Value |
|---|---|
PENDING | pending |
CONSUMED | consumed |
INVALIDATED | invalidated |
AuditOutcome
Result recorded on an audit log entry.
success is the recorded operation completing: a committed change, or a non-mutating one such as an access or an authentication that was allowed. failure is a change that was attempted and did not happen, or a post-commit side effect that failed. denied is an authorization or authentication refusal. attempt is an operation recorded before its result is known (long-running platform sync). conflict is a request rejected as a duplicate or stale (idempotent webhook replay, stale sync plan).
| Name | Value |
|---|---|
SUCCESS | success |
FAILURE | failure |
DENIED | denied |
ATTEMPT | attempt |
CONFLICT | conflict |
AuditAction
Verb recorded on an audit log entry: what was done to the resource.
delete is the hard delete of a resource that has no soft-delete lifecycle; soft_delete / permanent_delete / restore are the three steps of that lifecycle. start covers every way a run begins; which one is recorded in the entry's trigger_source detail, as a RunTriggerSource value, rather than as a separate verb.
| Name | Value |
|---|---|
CREATE | create |
UPDATE | update |
DELETE | delete |
SOFT_DELETE | soft_delete |
PERMANENT_DELETE | permanent_delete |
RESTORE | restore |
RENAME | rename |
MOVE | move |
BULK_CREATE | bulk_create |
BULK_RENAME | bulk_rename |
DUPLICATE | duplicate |
ANNOTATE | annotate |
UPLOAD | upload |
COMMIT | commit |
IMPORT | import |
EXPORT | export |
PLAN | plan |
APPLY | apply |
SYNC | sync |
DISCOVER | discover |
TEST | test |
SET_DEFAULT | set_default |
START | start |
CANCEL | cancel |
PAUSE | pause |
RESUME | resume |
TRIGGER | trigger |
RESOLVE | resolve |
REQUEST | request |
APPROVE | approve |
REJECT | reject |
EXPIRE | expire |
REVOKE | revoke |
ROTATE | rotate |
ROLLBACK | rollback |
UNLOCK | unlock |
PURGE | purge |
PRUNE | prune |
LINK_GIT | link_git |
CLEAR_GIT | clear_git |
UPDATE_GIT | update_git |
DETACH_GIT | detach_git |
ACCESS | access |
AUTHENTICATE | authenticate |
PROVISION | provision |
AuditResourceType
Kind of object an audit log entry is about.
Values are the audit log's own resource names, which do not always match ORM class names (webhook_endpoint, inventory_provider_config). api_route is used for access decisions, where the "object" is the route that was requested.
| Name | Value |
|---|---|
SITE | site |
DEVICE | device |
FLOW | flow |
FLOW_VERSION | flow_version |
FLOW_ATTACHMENT | flow_attachment |
FLOW_NOTIFICATION_SUBSCRIPTION | flow_notification_subscription |
RUN | run |
APPROVAL | approval |
SCHEDULE | schedule |
VARIABLE | variable |
VARIABLE_CONTEXT | variable_context |
SECRET | secret |
SECRET_BACKEND | secret_backend |
WEBHOOK_ENDPOINT | webhook_endpoint |
NOTIFICATION_DESTINATION | notification_destination |
GIT_REPOSITORY | git_repository |
FILE_REPOSITORY | file_repository |
FILE_REPOSITORY_FOLDER | file_repository_folder |
STORED_FILE | stored_file |
REGISTRY_CREDENTIAL | registry_credential |
CONTAINER_IMAGE | container_image |
BINARY_ARTIFACT | binary_artifact |
INVENTORY_PROVIDER_CONFIG | inventory_provider_config |
INVENTORY_PROVIDER_INVENTORY | inventory_provider_inventory |
ORGANIZATION | organization |
ORG_MEMBERSHIP | org_membership |
ORG_IDP_MAPPING | org_idp_mapping |
USER | user |
PERSONAL_ACCESS_TOKEN | personal_access_token |
PERMISSION_OVERRIDE | permission_override |
PERMISSION_ACTION_OVERRIDE | permission_action_override |
PLATFORM_SYNC_PROFILE | platform_sync_profile |
PLATFORM_SYNC_PLAN | platform_sync_plan |
PLATFORM_SYNC_DESTRUCTIVE_AUTHORIZATION | platform_sync_destructive_authorization |
CONFIG_EXCHANGE | config_exchange |
RUNTIME_ENV_KEY | runtime_env_key |
TF_STATE | tf_state |
AUDIT_LOG | audit_log |
API_ROUTE | api_route |
AuditAuthMethod
How the actor of an audit log entry was authenticated.
jwt is an interactive or service-account token from the identity provider, pat a personal access token, internal the shared worker/scheduler token on /internal routes, system a background job or bootstrap path with no request at all, dev_bypass the auth-disabled development mode, public an unauthenticated route such as an inbound webhook, and run_token a run step's short-lived token (a tf.* step's container writing its managed state).
| Name | Value |
|---|---|
JWT | jwt |
PAT | pat |
RUN_TOKEN | run_token |
INTERNAL | internal |
SYSTEM | system |
DEV_BYPASS | dev_bypass |
PUBLIC | public |