API Service
The Kubernetes API serves the shared Flow-Like routes, dependency-aware health probes and a separate metrics listener. It signs execution dispatches and issues scoped credentials; the Rust execution manager supervises the isolated runtime.
HTTP surfaces
Section titled “HTTP surfaces”| Surface | Default port | Purpose |
|---|---|---|
/api/v1/* | 8080 | Hub, app, event, execution, registry and administration routes |
/health/live | 8080 | Process liveness |
/health/ready | 8080 | Database, required schema and execution-state readiness |
/health/startup | 8080 | Process startup probe |
/swagger-ui | 8080 | Interactive API documentation |
/api-doc/openapi.json | 8080 | Generated OpenAPI document |
/r/*, /m/* | 8080 | Registered REST and MCP interfaces with per-registration authorization |
/metrics | 9090 | Prometheus metrics |
Workflow invocation uses app and event routes. The /api/v1/execution/* group
reports and queries runs; Kubernetes does not add a separate /jobs/* API.
Dependencies and startup
Section titled “Dependencies and startup”The API depends on SQL for durable platform state, Redis for queue and execution coordination, and object storage for metadata, content and artifacts. Bundled RustFS is initialized by the chart.
API init containers wait for the release’s database migration and RustFS initialization Jobs when enabled. Startup then validates configuration, explicit CORS origins, required API secrets and the execution signing keypair. Readiness checks required SQL tables and columns plus the execution-state store within two seconds.
The default interactive backend is the execution manager’s HTTP endpoint.
Background requests use the Redis queue bridge and the same manager. Both paths
assign a clean single-use sandbox. The reusable executor pool is reserved for
explicit trusted_shared mode.
Configuration
Section titled “Configuration”The chart injects database and Redis URLs, object-storage settings, execution
signing keys, manager configuration and service ports. Credentials are selected
through Secret references. api.runtimeConfig selects the complete hub/OIDC JSON
loaded at startup from a mounted Secret/ConfigMap, a Secret key or a configured
SecretStore reference. Restart API Pods after updating an external config source.
With no runtime source the API uses its embedded fallback.
api.corsAllowedOrigins must name the actual browser origins. Model-provider
Secrets configure the API’s hosted-model proxy; they do not enter isolated
runner Pods.
Extra runtime settings can use api.env and api.envFrom. Avoid duplicating
chart-owned environment names. See
Configuration and
Storage for their contracts.
Scale and drain
Section titled “Scale and drain”The API defaults to one replica with autoscaling disabled. Set
api.replicaCount, or enable api.autoscaling and configure its minimum,
maximum and utilization targets. The chart omits the Deployment replica count
when the HPA owns it.
Size the SQL connection pool for the largest API replica count and rollout surge.
API scaling does not increase execution capacity; use
executionManager.replicaCount, its active limit and execution node resources
for that.
The API handles SIGTERM through graceful HTTP shutdown. Keep edge connection timeouts compatible with streaming runs. Manager and queue-bridge drain periods separately cover accepted hour-long executions.
Access and diagnose
Section titled “Access and diagnose”kubectl port-forward service/flow-like-api 8083:8080 -n flow-likeIn another terminal:
curl -fsS http://localhost:8083/health/readycurl -fsS http://localhost:8083/api/v1/healthkubectl logs deployment/flow-like-api -n flow-like --tail=100kubectl rollout status deployment/flow-like-api -n flow-likeIf an API Pod remains in initialization, inspect migration and object-store Jobs. If readiness fails after startup, check SQL connectivity, schema and execution state. For refused executions, inspect manager warm capacity and queue-bridge logs.
Source map
Section titled “Source map”| Component | Location |
|---|---|
| Kubernetes API | apps/backend/kubernetes/api/src/ |
| Shared API hardening | apps/backend/shared/api_hardening.rs |
| Shared router | packages/api/src/lib.rs |
| Execution dispatch | packages/api/src/execution/ |
| Rust supervisor | apps/backend/execution-manager/src/ |
Continue with API Reference for live endpoint discovery and Monitoring for the dedicated metrics listener.