Create building block runner
POST/api/meshobjects/meshbuildingblockrunners
Create a new meshBuildingBlockRunner.
The spec.publicKey must be a valid RSA public key in PEM format (BEGIN PUBLIC KEY) or an X.509
certificate (BEGIN CERTIFICATE). meshStack uses this public key to encrypt secrets that are sent to
the runner at execution time.
The spec.workloadIdentityFederation section is optional. When provided, it configures the runner
to use short-lived federated identity tokens for cloud provider authentication instead of
long-lived credentials. At least one of gcp, aws, or azure must be populated when
workloadIdentityFederation is specified.
The subjectTemplate declares the subject the runner presents. Write
{{ workspaceIdentifier }} and {{ buildingBlockDefinitionUuid }} where the Building Block
Definition a run belongs to should appear, and nothing else inside the braces. A runner whose
tokens cannot carry that information registers a fixed subject instead, which is simply a
template without placeholders. meshStack resolves the template per definition version and publishes
the result as status.versions[].workloadIdentityFederation on the meshBuildingBlockDefinition, which
is what you target in a cloud provider trust policy.
The metadata.uuid must not be provided on creation. meshStack assigns a UUID automatically and
returns it in the response.
Authentication: This endpoint supports API Key authentication.
Request
Responses
- 201
201