Skip to content

API Service

The Kubernetes API serves the shared Flow-Like routes, dependency-aware health probes and a separate metrics listener. It signs execution dispatches and issues scoped credentials; the Rust execution manager supervises the isolated runtime.

SurfaceDefault portPurpose
/api/v1/*8080Hub, app, event, execution, registry and administration routes
/health/live8080Process liveness
/health/ready8080Database, required schema and execution-state readiness
/health/startup8080Process startup probe
/swagger-ui8080Interactive API documentation
/api-doc/openapi.json8080Generated OpenAPI document
/r/*, /m/*8080Registered REST and MCP interfaces with per-registration authorization
/metrics9090Prometheus metrics

Workflow invocation uses app and event routes. The /api/v1/execution/* group reports and queries runs; Kubernetes does not add a separate /jobs/* API.

The API depends on SQL for durable platform state, Redis for queue and execution coordination, and object storage for metadata, content and artifacts. Bundled RustFS is initialized by the chart.

API init containers wait for the release’s database migration and RustFS initialization Jobs when enabled. Startup then validates configuration, explicit CORS origins, required API secrets and the execution signing keypair. Readiness checks required SQL tables and columns plus the execution-state store within two seconds.

The default interactive backend is the execution manager’s HTTP endpoint. Background requests use the Redis queue bridge and the same manager. Both paths assign a clean single-use sandbox. The reusable executor pool is reserved for explicit trusted_shared mode.

The chart injects database and Redis URLs, object-storage settings, execution signing keys, manager configuration and service ports. Credentials are selected through Secret references. api.runtimeConfig selects the complete hub/OIDC JSON loaded at startup from a mounted Secret/ConfigMap, a Secret key or a configured SecretStore reference. Restart API Pods after updating an external config source. With no runtime source the API uses its embedded fallback.

api.corsAllowedOrigins must name the actual browser origins. Model-provider Secrets configure the API’s hosted-model proxy; they do not enter isolated runner Pods.

Extra runtime settings can use api.env and api.envFrom. Avoid duplicating chart-owned environment names. See Configuration and Storage for their contracts.

The API defaults to one replica with autoscaling disabled. Set api.replicaCount, or enable api.autoscaling and configure its minimum, maximum and utilization targets. The chart omits the Deployment replica count when the HPA owns it.

Size the SQL connection pool for the largest API replica count and rollout surge. API scaling does not increase execution capacity; use executionManager.replicaCount, its active limit and execution node resources for that.

The API handles SIGTERM through graceful HTTP shutdown. Keep edge connection timeouts compatible with streaming runs. Manager and queue-bridge drain periods separately cover accepted hour-long executions.

Terminal window
kubectl port-forward service/flow-like-api 8083:8080 -n flow-like

In another terminal:

Terminal window
curl -fsS http://localhost:8083/health/ready
curl -fsS http://localhost:8083/api/v1/health
kubectl logs deployment/flow-like-api -n flow-like --tail=100
kubectl rollout status deployment/flow-like-api -n flow-like

If an API Pod remains in initialization, inspect migration and object-store Jobs. If readiness fails after startup, check SQL connectivity, schema and execution state. For refused executions, inspect manager warm capacity and queue-bridge logs.

ComponentLocation
Kubernetes APIapps/backend/kubernetes/api/src/
Shared API hardeningapps/backend/shared/api_hardening.rs
Shared routerpackages/api/src/lib.rs
Execution dispatchpackages/api/src/execution/
Rust supervisorapps/backend/execution-manager/src/

Continue with API Reference for live endpoint discovery and Monitoring for the dedicated metrics listener.