Skip to main content
Glama

Create a Workload

create_workload

Create a serverless, standard, or stateful workload, or a scheduled job with type "cron" plus schedule (cron takes no autoscaling, timeoutSeconds, or debug). Containers go in containers[] and scaling in the autoscaling block. Set reachability in this call: public true or an explicit firewallConfig, otherwise nothing can reach it. Production defaults: readiness and liveness probes, CPU and memory sized to the runtime (the platform default is 50m and 128Mi), a metric matched to the traffic. Type and name are immutable. A standard HTTP app from an image, a repository, or files you wrote: deploy_app. A database: add_database, which also installs a Redis cache; other catalog products (queues, brokers, search, gateways): install_template.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
gvcYesGVC slug. If the user named none, list_resources (kind "gvc") and let them choose.
orgNoOrganization slug.
nameYesWorkload name. Immutable: renaming is delete and recreate, which loses the URL and internal DNS.
tagsNoOptional tags (key/value pairs such as env=prod).
typeNoWorkload type (default: standard — always-running). Use "cron" for a SCHEDULED JOB: then `schedule` is REQUIRED and the job-policy fields apply, while autoscaling/timeoutSeconds/debug do NOT (they are rejected — probes and autoscaling have no meaning for a cron run). vm is not supported.standard
debugNoEnable or disable spec.defaultOptions.debug. Not valid with type: "cron".
publicNotrue opens external inbound and outbound to 0.0.0.0/0. Mutually exclusive with firewallConfig. Omitted: no external access.
suspendNoEnable or disable spec.defaultOptions.suspend (no replicas run while suspended; for a cron workload this pauses scheduled runs)
scheduleNoREQUIRED when type is "cron" (and ONLY valid then): a NUMERIC 5-field cron expression like "0 */6 * * *" (no @daily macros, no MON/JAN names). Omit entirely for serverless/standard/stateful.
capacityAINoEnable or disable spec.defaultOptions.capacityAI — applies to every type (default ON for serverless/standard/cron; on cron the new reservation takes effect at the next scheduled run). Explicit true is rejected with the cpu metric and with GPUs.
containersYesRequired full container specs (1-8). Each item minimally needs name and image; all other container fields are optional. This is the only way to define containers — there are no flat image/cpu/port fields.
autoscalingNoAutoscaling configuration → spec.defaultOptions.autoscaling (metric, target, minScale, maxScale, scaleToZeroDelay, maxConcurrency, keda). This is the ONLY place scaling is configured. Omit to use platform defaults (minScale 1, maxScale 5).
descriptionNoWorkload description
historyLimitNoNumber of completed job instances to retain (default 5)
identityLinkNoIdentity the workload runs as, for cloud and secret access, e.g. //identity/my-id. For a secret, grant_workload_secret_access sets it.
restartPolicyNoWhat to do when a job instance fails
firewallConfigNoInbound/outbound access control. Access is restricted by default.
timeoutSecondsNoSet spec.defaultOptions.timeoutSeconds — max request duration (platform default 5s; serverless caps at 600)
concurrencyPolicyNoWhat to do when a run is due while a prior run is still active (default Forbid)
supportDynamicTagsNoEnable or disable spec.supportDynamicTags (detects image digest changes).
activeDeadlineSecondsNoMax seconds to wait for the job to complete before it is stopped

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okYes
dataNoThe full result. Read this, not only the summary.
detailsNo
summaryYes
nextStepsNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed98 schema fields changed
    • removedInput schema / $schema
      Removed value: -"http://json-schema.org/draft-07/schema#"
    • removedInput schema / additionalProperties
      Removed value: -false
    • removedInput schema / properties / autoscaling / additionalProperties
      Removed value: -false
    • removedInput schema / properties / autoscaling / properties / keda / additionalProperties
      Removed value: -false
    • changedInput schema / properties / autoscaling / properties / keda / description
      Previous value: -"KEDA scaling configuration (use with metric=\"keda\"; standard/stateful only). The GVC must enable KEDA FIRST — update_gvc with spec.keda.enabled: true. Trigger auth secrets are listed in the GVC spec.keda.secrets and referenced via authenticationRef.name. When a trigger source is itself a Control Plane workload, that workload's internal firewall must allow cpln://internal/keda in inboundAllowWorkload."New value: +"For metric keda on standard or stateful. The GVC needs spec.keda.enabled first (update_gvc); trigger auth secrets are listed in its spec.keda.secrets. A workload used as a trigger source must admit cpln://internal/keda. Shape: {triggers: [{type, metadata, name, metricType, authenticationRef: {name}}], advanced, fallback, pollingInterval, cooldownPeriod}."
    • removedInput schema / properties / autoscaling / properties / keda / properties
      Removed value: -{
      -  "advanced": {
      -    "additionalProperties": false,
      -    "properties": {
      -      "scalingModifiers": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "activationTarget": {
      -            "description": "New activation target value for the composed metric",
      -            "type": "string"
      -          },
      -          "formula": {
      -            "description": "Formula composing metrics together (mathematical/conditional statements)",
      -            "type": "string"
      -          },
      -          "metricType": {
      -            "enum": [
      -              "AverageValue",
      -              "Value",
      -              "Utilization"
      -            ],
      -            "type": "string"
      -          },
      -          "target": {
      -            "description": "New target value for the composed metric",
      -            "type": "string"
      -          }
      -        },
      -        "type": "object"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "cooldownPeriod": {
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "fallback": {
      -    "additionalProperties": false,
      -    "properties": {
      -      "behavior": {
      -        "enum": [
      -          "static",
      -          "currentReplicas",
      -          "currentReplicasIfHigher",
      -          "currentReplicasIfLower"
      -        ],
      -        "type": "string"
      -      },
      -      "failureThreshold": {
      -        "description": "Consecutive failures required to trigger fallback",
      -        "type": "integer"
      -      },
      -      "replicas": {
      -        "description": "Replica count to scale to when fallback triggers",
      -        "type": "integer"
      -      }
      -    },
      -    "required": [
      -      "failureThreshold",
      -      "replicas"
      -    ],
      -    "type": "object"
      -  },
      -  "initialCooldownPeriod": {
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "pollingInterval": {
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "triggers": {
      -    "description": "KEDA triggers used for scaling",
      -    "items": {
      -      "additionalProperties": false,
      -      "properties": {
      -        "authenticationRef": {
      -          "additionalProperties": false,
      -          "properties": {
      -            "name": {
      -              "description": "Name of a secret listed in the GVC spec.keda.secrets",
      -              "minLength": 1,
      -              "type": "string"
      -            }
      -          },
      -          "required": [
      -            "name"
      -          ],
      -          "type": "object"
      -        },
      -        "metadata": {
      -          "additionalProperties": {
      -            "type": "string"
      -          },
      -          "description": "Trigger configuration parameters",
      -          "type": "object"
      -        },
      -        "metricType": {
      -          "description": "Metric type used for scaling",
      -          "enum": [
      -            "AverageValue",
      -            "Value",
      -            "Utilization"
      -          ],
      -          "type": "string"
      -        },
      -        "name": {
      -          "description": "Optional trigger name",
      -          "type": "string"
      -        },
      -        "type": {
      -          "description": "KEDA trigger type, e.g. \"prometheus\", \"aws-sqs\"",
      -          "minLength": 1,
      -          "type": "string"
      -        },
      -        "useCachedMetrics": {
      -          "description": "Cache metric values during the polling interval",
      -          "type": "boolean"
      -        }
      -      },
      -      "required": [
      -        "type"
      -      ],
      -      "type": "object"
      -    },
      -    "type": "array"
      -  }
      -}
    • changedInput schema / properties / autoscaling / properties / metric / description
      Previous value: -"Single scaling metric (mutually exclusive with multi). Allowed values depend on the workload TYPE: serverless → concurrency, cpu, memory, rps, disabled; standard/stateful → cpu, memory, latency, rps, keda, disabled. concurrency is serverless-ONLY; latency, keda, and multi are standard/stateful-only. Omitted → serverless defaults to concurrency; standard/stateful default to cpu — and the cpu default silently disables Capacity AI. Choose the metric that matches the workload type and its traffic shape (rps/concurrency for HTTP, cpu/memory for compute)."New value: +"Single metric, exclusive with multi. serverless: concurrency (default), cpu, memory, rps, disabled. standard and stateful: cpu (turns Capacity AI off), memory, latency, rps, keda, disabled. Omitted on standard with Capacity AI on, it is disabled, which holds minScale replicas. rps or concurrency for HTTP, cpu or memory for compute."
    • removedInput schema / properties / autoscaling / properties / multi / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / autoscaling / properties / multi / minItems
      Removed value: -1
    • removedInput schema / properties / containers / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / command / maxLength
      Removed value: -256
    • removedInput schema / properties / containers / items / properties / cpu / maxLength
      Removed value: -20
    • removedInput schema / properties / containers / items / properties / cpu / pattern
      Removed value: -"^([0-9]+)(m|(\\.[0-9]{1,3}))?$"
    • changedInput schema / properties / containers / items / properties / env / description
      Previous value: -"Optional environment variables for this container. Omit to leave unset."New value: +"Optional environment variables for this container. Omit to leave unset. Grant access to each referenced secret with grant_workload_secret_access."
    • removedInput schema / properties / containers / items / properties / env / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / env / items / properties / name / maxLength
      Removed value: -120
    • removedInput schema / properties / containers / items / properties / env / items / properties / name / minLength
      Removed value: -1
    • removedInput schema / properties / containers / items / properties / env / items / properties / name / pattern
      Removed value: -"^[-._a-zA-Z][-._a-zA-Z0-9]*$"
    • changedInput schema / properties / containers / items / properties / env / items / properties / value / description
      Previous value: -"Literal value, or a secret reference like cpln://secret/<name>.<key>. Secret refs require the workload identity to have reveal permission or the deployment PAUSES — after create_workload, grant it with grant_workload_secret_access."New value: +"Non-sensitive literal value, or a secret reference like cpln://secret/<name>.<key>. Never send passwords, API keys, or tokens. The workload identity needs reveal permission on a referenced secret, or the deployment PAUSES."
    • removedInput schema / properties / containers / items / properties / env / items / properties / value / maxLength
      Removed value: -4096
    • removedInput schema / properties / containers / items / properties / gpu / additionalProperties
      Removed value: -false
    • changedInput schema / properties / containers / items / properties / gpu / description
      Previous value: -"Reserved GPU resources. Note: CapacityAI must be disabled and only one container per workload may use a GPU."New value: +"Reserved GPU resources. Note: CapacityAI must be disabled and only one container per workload may use a GPU. Shape: exactly one of nvidia {model: t4|a10g, quantity} or custom {resource, runtimeClass, quantity}."
    • removedInput schema / properties / containers / items / properties / gpu / properties
      Removed value: -{
      -  "custom": {
      -    "additionalProperties": false,
      -    "description": "Custom (non-NVIDIA) GPU resource specification",
      -    "properties": {
      -      "quantity": {
      -        "description": "Number of custom GPUs to allocate (default 1)",
      -        "maximum": 8,
      -        "minimum": 0,
      -        "type": "number"
      -      },
      -      "resource": {
      -        "description": "Custom GPU resource name (e.g., amd.com/gpu)",
      -        "maxLength": 64,
      -        "pattern": "^[a-zA-Z0-9./_-]*$",
      -        "type": "string"
      -      },
      -      "runtimeClass": {
      -        "description": "Runtime class for the custom GPU",
      -        "maxLength": 64,
      -        "pattern": "^[a-zA-Z0-9./]*$",
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "resource"
      -    ],
      -    "type": "object"
      -  },
      -  "nvidia": {
      -    "additionalProperties": false,
      -    "description": "NVIDIA GPU resource specification",
      -    "properties": {
      -      "model": {
      -        "description": "NVIDIA GPU model",
      -        "enum": [
      -          "t4",
      -          "a10g"
      -        ],
      -        "type": "string"
      -      },
      -      "quantity": {
      -        "description": "Number of NVIDIA GPUs to allocate (default 1)",
      -        "maximum": 4,
      -        "minimum": 0,
      -        "type": "number"
      -      }
      -    },
      -    "required": [
      -      "model"
      -    ],
      -    "type": "object"
      -  }
      -}
    • changedInput schema / properties / containers / items / properties / image / description
      Previous value: -"Image reference (required): org-internal = //image/NAME:TAG (long form /org/<org>/image/NAME:TAG also valid; no pull secret needed); public Docker Hub = bare (nginx:latest, never docker.io/...); other registries = exact host path — PRIVATE external registries need a pull secret on the GVC (docker, ecr, or gcp secret types only). Must be linux/amd64."New value: +"Image: //image/NAME:TAG for this org, or an exact external reference. A private external registry needs a docker, ecr, or gcp pull secret on the GVC."
    • removedInput schema / properties / containers / items / properties / image / minLength
      Removed value: -1
    • removedInput schema / properties / containers / items / properties / lifecycle / additionalProperties
      Removed value: -false
    • changedInput schema / properties / containers / items / properties / lifecycle / description
      Previous value: -"Lifecycle hooks for the container"New value: +"Lifecycle hooks for the container Shape: {postStart: {exec: {command: []}}, preStop: {exec: {command: []}}}. The default preStop runs sh -c \"sleep N\"; if it or a custom preStop fails, every container in the replica is killed at once."
    • removedInput schema / properties / containers / items / properties / lifecycle / properties
      Removed value: -{
      -  "postStart": {
      -    "additionalProperties": false,
      -    "description": "Action to perform after the container starts",
      -    "properties": {
      -      "exec": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "command": {
      -            "description": "Command run immediately after the container starts",
      -            "items": {
      -              "type": "string"
      -            },
      -            "type": "array"
      -          }
      -        },
      -        "required": [
      -          "command"
      -        ],
      -        "type": "object"
      -      }
      -    },
      -    "required": [
      -      "exec"
      -    ],
      -    "type": "object"
      -  },
      -  "preStop": {
      -    "additionalProperties": false,
      -    "description": "Action to perform before the container stops. When omitted the platform runs a default preStop of sh -c \"sleep N\" — an image without sleep (e.g. distroless) or a custom preStop that fails causes ALL containers in the replica to be SIGKILLed immediately.",
      -    "properties": {
      -      "exec": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "command": {
      -            "description": "Command run immediately before the container stops",
      -            "items": {
      -              "type": "string"
      -            },
      -            "type": "array"
      -          }
      -        },
      -        "required": [
      -          "command"
      -        ],
      -        "type": "object"
      -      }
      -    },
      -    "required": [
      -      "exec"
      -    ],
      -    "type": "object"
      -  }
      -}
    • removedInput schema / properties / containers / items / properties / livenessProbe / additionalProperties
      Removed value: -false
    • changedInput schema / properties / containers / items / properties / livenessProbe / description
      Previous value: -"Optional probe that restarts the container when it fails. If present, set exactly one handler."New value: +"Optional probe that restarts the container when it fails. Shape: exactly one of httpGet {path, port, httpHeaders: [{name, value}], scheme: HTTP|HTTPS}, tcpSocket {port}, grpc {port}, exec {command: []}; optional initialDelaySeconds, periodSeconds, timeoutSeconds, successThreshold, failureThreshold."
    • removedInput schema / properties / containers / items / properties / livenessProbe / properties
      Removed value: -{
      -  "exec": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: execute a command to check health (exit 0 = healthy). Use exactly one handler total.",
      -    "properties": {
      -      "command": {
      -        "description": "Command to execute for the health check",
      -        "items": {
      -          "type": "string"
      -        },
      -        "minItems": 1,
      -        "type": "array"
      -      }
      -    },
      -    "required": [
      -      "command"
      -    ],
      -    "type": "object"
      -  },
      -  "failureThreshold": {
      -    "description": "Consecutive failures to be considered failed (default 3)",
      -    "maximum": 20,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "grpc": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform a gRPC health check. Use exactly one handler total.",
      -    "properties": {
      -      "port": {
      -        "description": "Port to perform the gRPC health check on",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      }
      -    },
      -    "required": [
      -      "port"
      -    ],
      -    "type": "object"
      -  },
      -  "httpGet": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform an HTTP GET health check (2xx/3xx = healthy). Use exactly one handler total.",
      -    "properties": {
      -      "httpHeaders": {
      -        "description": "Custom HTTP headers to include in the health check request",
      -        "items": {
      -          "additionalProperties": false,
      -          "properties": {
      -            "name": {
      -              "description": "HTTP header name",
      -              "maxLength": 128,
      -              "type": "string"
      -            },
      -            "value": {
      -              "description": "HTTP header value",
      -              "maxLength": 128,
      -              "type": "string"
      -            }
      -          },
      -          "required": [
      -            "name",
      -            "value"
      -          ],
      -          "type": "object"
      -        },
      -        "type": "array"
      -      },
      -      "path": {
      -        "description": "HTTP path to request (default \"/\")",
      -        "maxLength": 256,
      -        "type": "string"
      -      },
      -      "port": {
      -        "description": "Port to perform the HTTP health check on (defaults to the container port)",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      },
      -      "scheme": {
      -        "description": "HTTP scheme to use (default HTTP)",
      -        "enum": [
      -          "HTTP",
      -          "HTTPS"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "initialDelaySeconds": {
      -    "description": "Seconds to wait before the first check (readiness default 10, liveness default 60)",
      -    "maximum": 600,
      -    "minimum": 0,
      -    "type": "integer"
      -  },
      -  "periodSeconds": {
      -    "description": "How often to perform the check (default 10)",
      -    "maximum": 600,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "successThreshold": {
      -    "description": "Consecutive successes to be considered healthy (default 1)",
      -    "maximum": 20,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "tcpSocket": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform a TCP socket health check. Use exactly one handler total.",
      -    "properties": {
      -      "port": {
      -        "description": "Port to perform the TCP socket check on (defaults to the container port)",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "timeoutSeconds": {
      -    "description": "Seconds after which the check times out (default 1)",
      -    "maximum": 600,
      -    "minimum": 1,
      -    "type": "integer"
      -  }
      -}
    • removedInput schema / properties / containers / items / properties / memory / maxLength
      Removed value: -20
    • removedInput schema / properties / containers / items / properties / memory / pattern
      Removed value: -"^[0-9]+(\\.[0-9]{1,3})?(G|M|k|Gi|Mi|Ki)?$"
    • removedInput schema / properties / containers / items / properties / metrics / additionalProperties
      Removed value: -false
    • changedInput schema / properties / containers / items / properties / metrics / description
      Previous value: -"Prometheus metrics scrape configuration for this container"New value: +"Prometheus metrics scrape configuration for this container Shape: {port, path (default /metrics), dropMetrics: [regex]}."
    • removedInput schema / properties / containers / items / properties / metrics / properties
      Removed value: -{
      -  "dropMetrics": {
      -    "description": "Drop metrics whose names match these regex patterns",
      -    "items": {
      -      "type": "string"
      -    },
      -    "type": "array"
      -  },
      -  "path": {
      -    "description": "HTTP path where Prometheus metrics are exposed (default /metrics)",
      -    "maxLength": 128,
      -    "type": "string"
      -  },
      -  "port": {
      -    "description": "Port where Prometheus metrics are exposed",
      -    "maximum": 65535,
      -    "minimum": 80,
      -    "type": "integer"
      -  }
      -}
    • removedInput schema / properties / containers / items / properties / metrics / required
      Removed value: -[
      -  "port"
      -]
    • removedInput schema / properties / containers / items / properties / minCpu / maxLength
      Removed value: -20
    • removedInput schema / properties / containers / items / properties / minCpu / pattern
      Removed value: -"^([0-9]+)(m|(\\.[0-9]{1,3}))?$"
    • removedInput schema / properties / containers / items / properties / minMemory / maxLength
      Removed value: -20
    • removedInput schema / properties / containers / items / properties / minMemory / pattern
      Removed value: -"^[0-9]+(\\.[0-9]{1,3})?(G|M|k|Gi|Mi|Ki)?$"
    • removedInput schema / properties / containers / items / properties / name / maxLength
      Removed value: -64
    • removedInput schema / properties / containers / items / properties / name / minLength
      Removed value: -2
    • removedInput schema / properties / containers / items / properties / name / pattern
      Removed value: -"^[a-z][a-z0-9-]*[a-z0-9]$"
    • removedInput schema / properties / containers / items / properties / ports / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / readinessProbe / additionalProperties
      Removed value: -false
    • changedInput schema / properties / containers / items / properties / readinessProbe / description
      Previous value: -"Optional probe that gates whether the container receives traffic. If present, set exactly one handler."New value: +"Optional probe that gates whether the container receives traffic. Shape: exactly one of httpGet {path, port, httpHeaders: [{name, value}], scheme: HTTP|HTTPS}, tcpSocket {port}, grpc {port}, exec {command: []}; optional initialDelaySeconds, periodSeconds, timeoutSeconds, successThreshold, failureThreshold."
    • removedInput schema / properties / containers / items / properties / readinessProbe / properties
      Removed value: -{
      -  "exec": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: execute a command to check health (exit 0 = healthy). Use exactly one handler total.",
      -    "properties": {
      -      "command": {
      -        "description": "Command to execute for the health check",
      -        "items": {
      -          "type": "string"
      -        },
      -        "minItems": 1,
      -        "type": "array"
      -      }
      -    },
      -    "required": [
      -      "command"
      -    ],
      -    "type": "object"
      -  },
      -  "failureThreshold": {
      -    "description": "Consecutive failures to be considered failed (default 3)",
      -    "maximum": 20,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "grpc": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform a gRPC health check. Use exactly one handler total.",
      -    "properties": {
      -      "port": {
      -        "description": "Port to perform the gRPC health check on",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      }
      -    },
      -    "required": [
      -      "port"
      -    ],
      -    "type": "object"
      -  },
      -  "httpGet": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform an HTTP GET health check (2xx/3xx = healthy). Use exactly one handler total.",
      -    "properties": {
      -      "httpHeaders": {
      -        "description": "Custom HTTP headers to include in the health check request",
      -        "items": {
      -          "additionalProperties": false,
      -          "properties": {
      -            "name": {
      -              "description": "HTTP header name",
      -              "maxLength": 128,
      -              "type": "string"
      -            },
      -            "value": {
      -              "description": "HTTP header value",
      -              "maxLength": 128,
      -              "type": "string"
      -            }
      -          },
      -          "required": [
      -            "name",
      -            "value"
      -          ],
      -          "type": "object"
      -        },
      -        "type": "array"
      -      },
      -      "path": {
      -        "description": "HTTP path to request (default \"/\")",
      -        "maxLength": 256,
      -        "type": "string"
      -      },
      -      "port": {
      -        "description": "Port to perform the HTTP health check on (defaults to the container port)",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      },
      -      "scheme": {
      -        "description": "HTTP scheme to use (default HTTP)",
      -        "enum": [
      -          "HTTP",
      -          "HTTPS"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "initialDelaySeconds": {
      -    "description": "Seconds to wait before the first check (readiness default 10, liveness default 60)",
      -    "maximum": 600,
      -    "minimum": 0,
      -    "type": "integer"
      -  },
      -  "periodSeconds": {
      -    "description": "How often to perform the check (default 10)",
      -    "maximum": 600,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "successThreshold": {
      -    "description": "Consecutive successes to be considered healthy (default 1)",
      -    "maximum": 20,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "tcpSocket": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform a TCP socket health check. Use exactly one handler total.",
      -    "properties": {
      -      "port": {
      -        "description": "Port to perform the TCP socket check on (defaults to the container port)",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "timeoutSeconds": {
      -    "description": "Seconds after which the check times out (default 1)",
      -    "maximum": 600,
      -    "minimum": 1,
      -    "type": "integer"
      -  }
      -}
    • changedInput schema / properties / containers / items / properties / volumes / description
      Previous value: -"Volume mounts for this container"New value: +"Volume mounts for this container. Shape: [{uri, path, recoveryPolicy: retain|recycle}], at most 15. uri: s3://BUCKET, gs://BUCKET, azureblob://ACCOUNT/CONTAINER, azurefs://ACCOUNT/SHARE, cpln://volumeset/NAME, cpln://secret/NAME, or scratch://NAME. path: absolute, not /dev, /tmp, or /var."
    • removedInput schema / properties / containers / items / properties / volumes / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / volumes / items / description
      Removed value: -"Mount an object store bucket, volume set, secret, or scratch volume into the container"
    • removedInput schema / properties / containers / items / properties / volumes / items / properties
      Removed value: -{
      -  "path": {
      -    "description": "Absolute mount path inside the container (required for non-vm workloads). /tmp, /var, /dev are reserved.",
      -    "minLength": 1,
      -    "type": "string"
      -  },
      -  "recoveryPolicy": {
      -    "description": "For persistent volumes: retain (default) or recycle existing data on replica creation",
      -    "enum": [
      -      "retain",
      -      "recycle"
      -    ],
      -    "type": "string"
      -  },
      -  "uri": {
      -    "description": "Volume source URI: s3://bucket, gs://bucket, azureblob://account/container, azurefs://account/share, cpln://volumeset/<name>, cpln://secret/<name>, or scratch://<name>.",
      -    "minLength": 1,
      -    "pattern": "^(s3|gs|azureblob|azurefs|cpln|scratch|k8s):\\/\\/.+",
      -    "type": "string"
      -  }
      -}
    • removedInput schema / properties / containers / items / properties / volumes / items / required
      Removed value: -[
      -  "uri",
      -  "path"
      -]
    • removedInput schema / properties / containers / items / properties / volumes / maxItems
      Removed value: -15
    • removedInput schema / properties / containers / items / properties / workingDir / maxLength
      Removed value: -128
    • removedInput schema / properties / containers / maxItems
      Removed value: -8
    • removedInput schema / properties / containers / minItems
      Removed value: -1
    • removedInput schema / properties / firewallConfig / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / external / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / external / properties / http / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / external / properties / http / properties / inboundHeaderFilter / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / external / properties / http / properties / inboundHeaderFilter / items / properties / key / maxLength
      Removed value: -128
    • removedInput schema / properties / firewallConfig / properties / external / properties / inboundAllowCIDR / maxItems
      Removed value: -250
    • removedInput schema / properties / firewallConfig / properties / external / properties / outboundAllowHostname / items / maxLength
      Removed value: -128
    • removedInput schema / properties / firewallConfig / properties / external / properties / outboundAllowHostname / items / pattern
      Removed value: -"^(?![0-9]+$)(?!.*-$)([*]?)(?!-)[a-z0-9-.]+$"
    • removedInput schema / properties / firewallConfig / properties / external / properties / outboundAllowPort / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / internal / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / internal / properties / inboundAllowWorkload / items / maxLength
      Removed value: -256
    • removedInput schema / properties / firewallConfig / properties / internal / properties / inboundAllowWorkload / items / minLength
      Removed value: -1
    • changedInput schema / properties / gvc / description
      Previous value: -"GVC slug (lowercase kebab-case). Use the GVC the user named; otherwise discover with list_resources (kind=\"gvc\") and let them choose — never guess (a wrong GVC targets the wrong environment)."New value: +"GVC slug. If the user named none, list_resources (kind \"gvc\") and let them choose."
    • removedInput schema / properties / gvc / maxLength
      Removed value: -63
    • removedInput schema / properties / gvc / minLength
      Removed value: -1
    • removedInput schema / properties / gvc / pattern
      Removed value: -"^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$"
    • changedInput schema / properties / identityLink / description
      Previous value: -"Identity link granting 3rd-party cloud resource access, e.g. //identity/my-id"New value: +"Identity the workload runs as, for cloud and secret access, e.g. //identity/my-id. For a secret, grant_workload_secret_access sets it."
    • removedInput schema / properties / identityLink / maxLength
      Removed value: -256
    • removedInput schema / properties / identityLink / minLength
      Removed value: -1
    • removedInput schema / properties / identityLink / pattern
      Removed value: -"^(\\/org\\/[^/]+\\/.+|\\/\\/.+)$"
    • changedInput schema / properties / name / description
      Previous value: -"Workload name (lowercase kebab-case, must start with a letter, max 49 chars, cannot end with -headless). The name is IMMUTABLE — \"renaming\" requires delete + recreate (loses public URL, internal DNS, policy targetLinks)."New value: +"Workload name. Immutable: renaming is delete and recreate, which loses the URL and internal DNS."
    • removedInput schema / properties / name / maxLength
      Removed value: -49
    • removedInput schema / properties / name / minLength
      Removed value: -2
    • removedInput schema / properties / name / pattern
      Removed value: -"^[a-z]([-a-z0-9])*[a-z0-9]$"
    • changedInput schema / properties / org / description
      Previous value: -"Organization slug (lowercase kebab-case). NEVER guess — if the user has not named one, ask. On org-not-found, stop and ask; do not retry variants."New value: +"Organization slug."
    • removedInput schema / properties / org / maxLength
      Removed value: -63
    • removedInput schema / properties / org / minLength
      Removed value: -1
    • removedInput schema / properties / org / pattern
      Removed value: -"^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$"
    • changedInput schema / properties / public / description
      Previous value: -"Convenience shortcut: opens the external firewall BOTH ways — inbound 0.0.0.0/0 AND outbound 0.0.0.0/0 (a public service almost always needs both directions). Mutually exclusive with firewallConfig, and an explicit firewallConfig overrides it. OMITTED = no external access (deny-by-default) — decide exposure here, at create time; do not create closed and patch the firewall open afterward."New value: +"true opens external inbound and outbound to 0.0.0.0/0. Mutually exclusive with firewallConfig. Omitted: no external access."
    • removedInput schema / properties / schedule / minLength
      Removed value: -1
    • removedInput schema / properties / tags / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / tags / items / properties / key / minLength
      Removed value: -1
    • removedInput schema / properties / tags / maxItems
      Removed value: -50
    • changedInput schema / required
      Previous value: -[
      -  "org",
      -  "gvc",
      -  "name",
      -  "containers"
      -]New value: +[
      +  "gvc",
      +  "name",
      +  "containers"
      +]
    • removedOutput schema / $schema
      Removed value: -"http://json-schema.org/draft-07/schema#"
    • removedOutput schema / additionalProperties
      Removed value: -false
    • changedOutput schema / properties / data / description
      Previous value: -"The full machine-readable result — list rows, the resource object, query results. Read THIS, not just the summary."New value: +"The full result. Read this, not only the summary."
    • addedOutput schema / properties / details
      Added value: +{
      +  "type": "string"
      +}
    • removedOutput schema / properties / nextSteps / description
      Removed value: -"Recommended follow-up actions for this task, in order."
    • removedOutput schema / properties / ok / description
      Removed value: -"Whether the call succeeded."
    • removedOutput schema / properties / summary / description
      Removed value: -"One-line summary of the result."
  2. Changed3 schema fields changed
    • changedInput schema / properties / capacityAI / description
      Previous value: -"Enable or disable spec.defaultOptions.capacityAI (default ON for serverless/standard, stripped on stateful/cron; explicit true is rejected with the cpu metric and with GPUs). Not valid with type: \"cron\"."New value: +"Enable or disable spec.defaultOptions.capacityAI — applies to every type (default ON for serverless/standard/cron; on cron the new reservation takes effect at the next scheduled run). Explicit true is rejected with the cpu metric and with GPUs."
    • changedInput schema / properties / containers / items / properties / gpu / properties / custom / properties / resource / pattern
      Previous value: -"^[a-zA-Z0-9./]*$"New value: +"^[a-zA-Z0-9./_-]*$"
    • changedInput schema / properties / type / description
      Previous value: -"Workload type (default: standard — always-running). Use \"cron\" for a SCHEDULED JOB: then `schedule` is REQUIRED and the job-policy fields apply, while autoscaling/capacityAI/timeoutSeconds/debug do NOT (they are rejected — probes and autoscaling have no meaning for a cron run). vm is not supported."New value: +"Workload type (default: standard — always-running). Use \"cron\" for a SCHEDULED JOB: then `schedule` is REQUIRED and the job-policy fields apply, while autoscaling/timeoutSeconds/debug do NOT (they are rejected — probes and autoscaling have no meaning for a cron run). vm is not supported."
  3. Changed1 schema field changed
    • changedInput schema / properties / containers / items / properties / env / items / properties / value / description
      Previous value: -"Literal value, or a secret reference like cpln://secret/<name>.<key>. Secret refs require the workload identity to have reveal permission or the deployment PAUSES — after create_workload, grant it with workload_reveal_secret."New value: +"Literal value, or a secret reference like cpln://secret/<name>.<key>. Secret refs require the workload identity to have reveal permission or the deployment PAUSES — after create_workload, grant it with grant_workload_secret_access."
  4. First observed

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already mark this as non-read-only and non-destructive, but the description adds valuable behavioral context: cron workloads cannot use autoscaling/timeoutSeconds/debug, reachability defaults to no access unless public or firewallConfig is set, type and name are immutable, and production defaults include probes and right-sized resources. No annotation contradiction exists.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but front-loaded: it opens with what is created, then covers critical call-time constraints, then routes to alternatives. Every sentence carries operational weight, with no filler despite the tool's complexity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the high parameter count, full schema coverage, nested objects, and the presence of an output schema, the description covers all the non-schema context an agent needs: sibling routing, immutability, cron restrictions, reachability defaults, and production defaults. Nothing necessary for correct invocation is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all 21 parameters thoroughly. The description still adds cross-field meaning, such as type/name immutability, cron exclusions, reachability requirements, and the placement of containers and autoscaling, which is slightly beyond what the individual schema fields state.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb+resource (create a workload) and immediately enumerates the supported variants: serverless, standard, stateful, and cron. It also distinguishes this tool from siblings by naming deploy_app, add_database, and install_template with their respective use cases.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It provides explicit routing: standard HTTP apps from an image/repo/files go to deploy_app; databases go to add_database; other catalog products go to install_template. It also states the critical reachability rule for this call, removing ambiguity about when and how to use create_workload.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.