Skip to content

Vocabulary ​

The canonical enumerations shared across the API, worker, scheduler, and UI, defined in packages/core/enums.py. Statuses, phases, node types, outcomes, and event kinds used anywhere in the platform come from this vocabulary.

EventKind ​

Types of events emitted during workflow execution.

NameValue
STAGE_CHANGEstage_change
LOGlog
ERRORerror
NOTIFICATIONnotification
PROGRESSprogress
GRAPH_FORK_SPLITgraph.fork_split
GRAPH_JOIN_ARRIVALgraph.join_arrival
GRAPH_JOIN_COMPLETEgraph.join_complete

Transport ​

Device communication transports.

NameValue
SSHssh
NETCONFnetconf
GNMIgnmi

ArtifactKind ​

Types of artifacts captured during evidence collection.

NameValue
CLI_OUTPUTcli_output
FACTS_JSONfacts_json
TRANSPORT_METAtransport_meta
STEP_RESULTstep_result
POLL_RESULTpoll_result
CONNECTIVITY_MONITORconnectivity_monitor
COMPARISON_RESULTcomparison_result
ASSERTION_RESULTassertion_result
CONTAINER_OUTPUTcontainer_output
DOWNLOADABLE_FILEdownloadable_file
EGRESS_REPORTegress_report

StepStatus ​

Execution status of a step run.

NameValue
PENDINGPENDING
RUNNINGRUNNING
SUCCESSSUCCESS
FAILEDFAILED
SKIPPEDSKIPPED
CANCELLEDCANCELLED

RunStatus ​

Execution status of a flow run.

NameValue
PENDINGPENDING
RUNNINGRUNNING
PAUSEDPAUSED
WAITING_APPROVALWAITING_APPROVAL
SUCCESSSUCCESS
FAILEDFAILED
CANCELLEDCANCELLED

RunTriggerSource ​

What started a flow run.

The five ways a run can begin, named once so admission checks can switch on them instead of sniffing created_by. manual is a person (or a script holding their token) calling POST /runs; run_now is a person pressing "Run now" on a schedule, which is still the schedule's own trigger and so stays distinct from manual; flow is a nested child run created by a parent's flow.run step.

Recorded on an audit entry as its trigger_source detail (see AuditAction), and read by apps/api/services/manual_run_policy.py to decide whether a flow that refuses hand-started runs admits this one.

NameValue
MANUALmanual
RUN_NOWrun_now
SCHEDULEschedule
WEBHOOKwebhook
FLOWflow

ExecutionAffinity ​

Worker-placement preference for a flow run or an individual step.

Controls which Temporal task queue a step's execute activity is dispatched to, and therefore which worker host runs it.

  • distributed: any worker may pick up the step (default; today's behavior). Steps cannot use the per-run shared workspace because they may run on a different host.
  • shared: all shared steps of a run are pinned to one randomly chosen worker and share a per-run workspace volume mounted at /shared.
  • explicit: pin to a named worker (see execution_worker). Reserved for the multi-host future; today validated against the single worker.
NameValue
DISTRIBUTEDdistributed
SHAREDshared
EXPLICITexplicit

MaintenanceJobStatus ​

Persisted execution status for internal maintenance jobs.

NameValue
RUNNINGRUNNING
SUCCESSSUCCESS
FAILEDFAILED

MaintenanceJobHealth ​

Derived health state for internal maintenance jobs.

NameValue
HEALTHYhealthy
FAILEDfailed
OVERDUEoverdue
RUNNINGrunning
STALE_RUNNINGstale_running
DISABLEDdisabled
NEVER_RUNnever_run

Capability ​

Inventory provider capabilities.

NameValue
READread
QUERYquery
WRITEwrite
WEBHOOKwebhook
DISCOVERdiscover
DELTAdelta

ResourceType ​

Inventory provider resource families.

NameValue
DEVICEdevice
SITEsite
IP_PREFIXip_prefix
IP_ADDRESSip_address
VLANvlan
CONTACTcontact

ProviderErrorCode ​

Stable provider error envelope codes.

NameValue
TIMEOUTtimeout
AUTH_FAILEDauth_failed
TLS_FAILEDtls_failed
NOT_FOUNDnot_found
PAGINATION_FAILEDpagination_failed
MALFORMED_QUERYmalformed_query
SCHEMA_VALIDATION_FAILEDschema_validation_failed
UNAVAILABLEunavailable

MaintenanceState ​

Local maintenance marker for inventory identity rows.

NameValue
ACTIVEactive
MAINTENANCEmaintenance
DISABLEDdisabled

EdgeType ​

Type of edge in a flow graph.

execution: Normal execution edge - routes tokens and counts toward join inputs. termination: Monitor termination edge - when the target join fires, attached monitors are stopped. Does not route tokens or count as join input.

NameValue
EXECUTIONexecution
TERMINATIONtermination

MonitorScheduleMode ​

How a monitor determines when to stop.

COUNT: Run exactly N ticks, then complete and route token to successors. Monitor self-terminates after count is reached.

DURATION: Run for duration_s total, then complete and route token to successors. Monitor self-terminates after duration elapses.

UNTIL_JOIN: Fire-and-forget background monitor. The join node handles termination when all (or any, depending on join mode) regular branches have arrived. Does NOT route token - join does not count this as an incoming branch. Monitor is stopped by the join after it processes its regular inputs.

Note: All monitors are automatically stopped when the run completes (success/failure) via stop_run_monitors activity, so explicit termination is only needed for mid-run control.

NameValue
COUNTcount
DURATIONduration
UNTIL_JOINuntil_join

MonitorTargetType ​

How a monitor target is specified.

NameValue
ROLErole
IPip

MonitorAddressKind ​

Which address to use when resolving a role-based target.

NameValue
MGMTmgmt
PRIMARYprimary
LOOPBACKloopback
CUSTOMcustom

MonitorAddressFamily ​

IP address family preference.

NameValue
AUTOauto
IPV4ipv4
IPV6ipv6

InterfaceNodeKind ​

Node kinds in the Flow Interface Builder authoring graph.

NameValue
SECTIONsection
FIELDfield
CONDITIONcondition
OPTION_SOURCEoption_source
VALIDATIONvalidation
NOTEnote

InterfaceEdgeSemanticType ​

Semantic type of an edge in the Flow Interface Builder graph.

Only relation types the compiler actually implements are listed; a new type must land together with its compiler + runtime support. Stored graphs containing retired/unknown types still load — the compiler skips those relations and reports an UNSUPPORTED_EDGE_RELATION warning.

options_filter: Source field value filters the target field's options. visible_when: Source field controls whether target field is shown. enabled_when: Source field controls whether target field is editable. required_when: Source field controls whether target field is required.

NameValue
OPTIONS_FILTERoptions_filter
VISIBLE_WHENvisible_when
ENABLED_WHENenabled_when
REQUIRED_WHENrequired_when

InterfaceProblemSeverity ​

Severity of a validation problem produced by the interface graph compiler.

NameValue
ERRORerror
WARNINGwarning
INFOinfo

MonitorCheckId ​

Built-in connectivity check types.

NameValue
ICMP_PINGicmp_ping
TCP_CONNECTtcp_connect
DNS_RESOLVEdns_resolve
HTTP_HEALTHhttp_health
TLS_HANDSHAKEtls_handshake
SSH_BANNERssh_banner

MonitorStatus ​

Status of a monitor instance.

NameValue
PENDINGpending
RUNNINGrunning
PAUSEDpaused
STOPPEDstopped
COMPLETEDcompleted
FAILEDfailed

ApprovalStatus ​

Status of an approval request.

NameValue
PENDINGPENDING
APPROVEDAPPROVED
REJECTEDREJECTED
EXPIREDEXPIRED
CANCELLEDCANCELLED

ScheduleType ​

Types of schedule cadence.

NameValue
ONE_TIMEone_time
RECURRINGrecurring

ScheduleStatus ​

Lifecycle status for schedules.

NameValue
ACTIVEactive
DISABLEDdisabled
COMPLETEDcompleted

FlowGraphNodeType ​

Type of node in a flow graph.

NameValue
STARTstart
STEPstep
APPROVALapproval
PAUSEpause
TERMINALterminal
FORKfork
JOINjoin
GROUPgroup
BRANCHbranch
LOOPloop
LOOP_ENDloop_end
SET_VARSset_vars

BranchMode ​

How a branch node selects its outgoing case.

RULES: Ordered per-case boolean conditions; first true case wins (if/elif). VALUE: One expression evaluated once, compared against per-case values (switch).

NameValue
RULESrules
VALUEvalue

LoopMode ​

How a loop node decides whether to run another iteration.

WHILE: Check the condition before each iteration (0..N runs). UNTIL: Run the body, then check the condition (do-while, 1..N runs). COUNT: Run a fixed number of iterations. FOR_EACH: Iterate over the items produced by an expression.

NameValue
WHILEwhile
UNTILuntil
COUNTcount
FOR_EACHfor_each

LoopBodyFailurePolicy ​

What a loop does when a body step fails without a wired failure edge.

FAIL: Fail the whole run (default; matches non-loop behavior). BREAK: Exit the loop via its 'done' outcome (reserved; rejected at commit). CONTINUE: Skip to the next iteration (reserved; rejected at commit).

Commit validation accepts only FAIL; BREAK and CONTINUE are reserved for forward compatibility and rejected.

NameValue
FAILfail
BREAKbreak
CONTINUEcontinue

ParallelIterationFailurePolicy ​

What a parallel loop does when one iteration fails.

DRAIN: Stop dispatching new iterations, let in-flight ones finish, then fail the loop (default). CANCEL: Cancel the in-flight iterations and fail the loop immediately. CONTINUE: Run every remaining iteration, then fail the loop reporting all failed iterations.

Only meaningful when max_parallel_iterations > 1; sequential loops keep their existing failure behavior.

NameValue
DRAINdrain
CANCELcancel
CONTINUEcontinue

JoinMode ​

How a join node waits for incoming branches.

ALL: Wait for all incoming branches to complete ANY: Continue when any single branch completes successfully

NameValue
ALLall
ANYany

JoinFailurePolicy ​

How a join node handles failed branches.

PROPAGATE: If any branch fails, the join fails after all complete FAIL_FAST: Fail immediately when any branch fails IGNORE_FAILURES: Continue if at least one branch succeeds (with ANY mode)

NameValue
PROPAGATEpropagate
FAIL_FASTfail_fast
IGNORE_FAILURESignore_failures

JoinCancelPolicy ​

What to do with remaining branches when join condition is met.

CANCEL_OTHERS: Cancel remaining branches when condition met (useful with ANY) WAIT: Wait for all branches to complete regardless

NameValue
CANCEL_OTHERScancel_others
WAITwait

FlowGraphOutcome ​

Canonical outcomes for graph node execution.

These are the standard outcomes that nodes produce. Edges attach to outcomes via source_outcome.

NameValue
STARTstart
SUCCESSsuccess
FAILUREfailure
CANCELLEDcancelled
APPROVEDapproved
REJECTEDrejected
EXPIREDexpired
FORKfork
JOINEDjoined
JOIN_FAILEDjoin_failed
ELSEelse
ERRORerror
ITERATEiterate
DONEdone
MAX_ITERATIONSmax_iterations

NotificationDestinationType ​

Types of notification destinations.

EMAIL: Send via SMTP SHOUTRRR: Use Shoutrrr CLI for arbitrary services (Discord, Slack, etc.) OUTGOING_WEBHOOK: Send HTTP requests to arbitrary endpoints

NameValue
EMAILemail
SHOUTRRRshoutrrr
OUTGOING_WEBHOOKoutgoing_webhook

NotificationEvent ​

Events that can trigger notifications.

Run lifecycle events and approval events.

NameValue
RUN_STARTEDrun.started
RUN_PAUSEDrun.paused
RUN_RESUMEDrun.resumed
RUN_CANCELLEDrun.cancelled
RUN_FAILEDrun.failed
RUN_COMPLETEDrun.completed
APPROVAL_REQUESTEDapproval.requested
APPROVAL_APPROVEDapproval.approved
APPROVAL_REJECTEDapproval.rejected
APPROVAL_EXPIREDapproval.expired

WebhookAuthMode ​

Authentication mode for inbound webhook verification.

NameValue
HMAC_SHA256hmac_sha256
BEARERbearer

WebhookTargetType ​

Concrete target type linked to a webhook endpoint.

NameValue
FLOWflow

SyncMode ​

Repository sync mode.

  • SYNCED: Repository is kept in sync with upstream and changes are applied.
  • READONLY: Repository content is available but cannot be mutated via the API.
  • DETACHED: Repository is tracked but not actively synced.
NameValue
SYNCEDsynced
READONLYreadonly
DETACHEDdetached

ConflictPolicy ​

Policy to resolve conflicts when syncing remote changes.

  • REJECT_DIRTY: Reject operations if local changes would be overwritten.
  • OVERWRITE: Overwrite local changes with remote content.
  • SKIP: Skip conflicting flows without applying changes.
  • FORCE: Overwrite local changes with remote (force).
NameValue
REJECT_DIRTYreject_dirty
OVERWRITEoverwrite
SKIPskip
FORCEforce

PlatformSyncMode ​

Authority mode for platform sync operations.

NameValue
BACKUPbackup
MIRRORmirror
BIDIRECTIONALbidirectional

PlatformSyncOperation ​

Platform sync operation kind.

NameValue
EXPORTexport
PLANplan
APPLYapply

PlatformSyncTriggerSource ​

How a platform sync run was triggered.

NameValue
MANUALmanual
SCHEDULEschedule

PlatformSyncRunStatus ​

Lifecycle status for platform sync runs.

NameValue
RUNNINGrunning
SUCCESSsuccess
NOOPnoop
FAILEDfailed
CONFLICTconflict
BLOCKEDblocked

PlatformSyncChangeKind ​

Change type detected by platform sync planning.

NameValue
CREATEcreate
UPDATEupdate
DELETEdelete
NOOPnoop
CONFLICTconflict

PlatformSyncResourceFamily ​

Supported resource families for platform sync bundles.

NameValue
FLOWflow
SITEsite
DEVICEdevice
SECRETsecret
SECRET_BACKENDsecret_backend
VARIABLEvariable
SCHEDULEschedule
NOTIFICATION_DESTINATIONnotification_destination
FLOW_NOTIFICATION_SUBSCRIPTIONflow_notification_subscription
WEBHOOK_ENDPOINTwebhook_endpoint
FILE_REPOSITORYfile_repository
GIT_REPOSITORYgit_repository
REGISTRY_CREDENTIALregistry_credential
PERMISSION_OVERRIDEpermission_override
PERMISSION_ACTION_OVERRIDEpermission_action_override
INVENTORY_PROVIDER_CONFIGinventory_provider_config
PLATFORM_SYNC_PROFILEplatform_sync_profile

PlatformSyncDestructivePolicy ​

Policy for destructive apply behavior.

NameValue
BLOCKblock
ALLOW_WITH_CONFIRMATIONallow_with_confirmation
ALLOW_AUTOMATEDallow_automated

PlatformSyncConflictResolution ​

Conflict resolution preference for bidirectional sync.

NameValue
PREFER_GITprefer_git
PREFER_PLATFORMprefer_platform
MANUAL_EDITmanual_edit

ConfigExchangeActorKind ​

Actor kind for configuration exchange operations.

NameValue
USERuser
SERVICEservice

ConfigExchangeLayout ​

Layout options for configuration exchange payloads.

NameValue
SINGLE_YAMLsingle_yaml
EXPLODED_PLATFORMexploded_platform
FLOW_YAMLflow_yaml

ConfigExchangeOperation ​

Operation types for configuration exchange.

NameValue
EXPORTexport
IMPORTimport
PLANplan
APPLYapply

ConfigExchangeScope ​

Scope for configuration exchange operations.

NameValue
PLATFORMplatform
FLOWflow

ConfigExchangeTransport ​

Transport options for configuration exchange payload delivery.

NameValue
DOWNLOADdownload
UPLOADupload
INLINEinline
GITgit

ConfigExchangePlanStatus ​

Lifecycle status for configuration exchange import plans.

NameValue
PENDINGpending
CONSUMEDconsumed
INVALIDATEDinvalidated

AuditOutcome ​

Result recorded on an audit log entry.

success is the recorded operation completing: a committed change, or a non-mutating one such as an access or an authentication that was allowed. failure is a change that was attempted and did not happen, or a post-commit side effect that failed. denied is an authorization or authentication refusal. attempt is an operation recorded before its result is known (long-running platform sync). conflict is a request rejected as a duplicate or stale (idempotent webhook replay, stale sync plan).

NameValue
SUCCESSsuccess
FAILUREfailure
DENIEDdenied
ATTEMPTattempt
CONFLICTconflict

AuditAction ​

Verb recorded on an audit log entry: what was done to the resource.

delete is the hard delete of a resource that has no soft-delete lifecycle; soft_delete / permanent_delete / restore are the three steps of that lifecycle. start covers every way a run begins; which one is recorded in the entry's trigger_source detail, as a RunTriggerSource value, rather than as a separate verb.

NameValue
CREATEcreate
UPDATEupdate
DELETEdelete
SOFT_DELETEsoft_delete
PERMANENT_DELETEpermanent_delete
RESTORErestore
RENAMErename
MOVEmove
BULK_CREATEbulk_create
BULK_RENAMEbulk_rename
DUPLICATEduplicate
ANNOTATEannotate
UPLOADupload
COMMITcommit
IMPORTimport
EXPORTexport
PLANplan
APPLYapply
SYNCsync
DISCOVERdiscover
TESTtest
SET_DEFAULTset_default
STARTstart
CANCELcancel
PAUSEpause
RESUMEresume
TRIGGERtrigger
RESOLVEresolve
REQUESTrequest
APPROVEapprove
REJECTreject
EXPIREexpire
REVOKErevoke
ROTATErotate
ROLLBACKrollback
UNLOCKunlock
PURGEpurge
PRUNEprune
LINK_GITlink_git
CLEAR_GITclear_git
UPDATE_GITupdate_git
DETACH_GITdetach_git
ACCESSaccess
AUTHENTICATEauthenticate
PROVISIONprovision

AuditResourceType ​

Kind of object an audit log entry is about.

Values are the audit log's own resource names, which do not always match ORM class names (webhook_endpoint, inventory_provider_config). api_route is used for access decisions, where the "object" is the route that was requested.

NameValue
SITEsite
DEVICEdevice
FLOWflow
FLOW_VERSIONflow_version
FLOW_ATTACHMENTflow_attachment
FLOW_NOTIFICATION_SUBSCRIPTIONflow_notification_subscription
RUNrun
APPROVALapproval
SCHEDULEschedule
VARIABLEvariable
VARIABLE_CONTEXTvariable_context
SECRETsecret
SECRET_BACKENDsecret_backend
WEBHOOK_ENDPOINTwebhook_endpoint
NOTIFICATION_DESTINATIONnotification_destination
GIT_REPOSITORYgit_repository
FILE_REPOSITORYfile_repository
FILE_REPOSITORY_FOLDERfile_repository_folder
STORED_FILEstored_file
REGISTRY_CREDENTIALregistry_credential
CONTAINER_IMAGEcontainer_image
BINARY_ARTIFACTbinary_artifact
INVENTORY_PROVIDER_CONFIGinventory_provider_config
INVENTORY_PROVIDER_INVENTORYinventory_provider_inventory
ORGANIZATIONorganization
ORG_MEMBERSHIPorg_membership
ORG_IDP_MAPPINGorg_idp_mapping
USERuser
PERSONAL_ACCESS_TOKENpersonal_access_token
PERMISSION_OVERRIDEpermission_override
PERMISSION_ACTION_OVERRIDEpermission_action_override
PLATFORM_SYNC_PROFILEplatform_sync_profile
PLATFORM_SYNC_PLANplatform_sync_plan
PLATFORM_SYNC_DESTRUCTIVE_AUTHORIZATIONplatform_sync_destructive_authorization
CONFIG_EXCHANGEconfig_exchange
RUNTIME_ENV_KEYruntime_env_key
TF_STATEtf_state
AUDIT_LOGaudit_log
API_ROUTEapi_route

AuditAuthMethod ​

How the actor of an audit log entry was authenticated.

jwt is an interactive or service-account token from the identity provider, pat a personal access token, internal the shared worker/scheduler token on /internal routes, system a background job or bootstrap path with no request at all, dev_bypass the auth-disabled development mode, public an unauthenticated route such as an inbound webhook, and run_token a run step's short-lived token (a tf.* step's container writing its managed state).

NameValue
JWTjwt
PATpat
RUN_TOKENrun_token
INTERNALinternal
SYSTEMsystem
DEV_BYPASSdev_bypass
PUBLICpublic

Released as open source under the AGPL-3.0-or-later license. Development is sponsored by Rexonix s.r.o.. Contact — [email protected].