Skip to main content
Glama

Update a Workload

update_workload
DestructiveIdempotent

Update a workload (PATCH: only the fields passed change). Type and name are immutable. A cron workload takes schedule, job policy, suspend, capacityAI, and containers here, not autoscaling, timeoutSeconds, or debug; schedule and job fields are rejected on other types. Read it with get_resource first so a rollback exists, and never downgrade probes or autoscaling silently. loadBalancer, sidecar, extras, localOptions, rolloutOptions, securityOptions, and requestRetryPolicy have their own configure_workload_* tools. A new image or exposure for an app: deploy_app.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
gvcYesGVC slug. If the user named none, list_resources (kind "gvc") and let them choose.
orgNoOrganization slug.
nameYesWorkload name. Immutable: renaming is delete and recreate, which loses the URL and internal DNS.
tagsNoAdd or update tags without replacing the full set. Submit an empty list to clear all tags.
debugNoEnable or disable spec.defaultOptions.debug. Not valid for a cron workload.
publicNoConvenience shortcut: opens the external firewall BOTH ways — inbound 0.0.0.0/0 AND outbound 0.0.0.0/0. Mutually exclusive with firewallConfig (an explicit firewallConfig overrides it).
suspendNoEnable or disable spec.defaultOptions.suspend (for a cron workload, pauses/resumes scheduled runs)
scheduleNoNew cron schedule (NUMERIC 5-field expression, e.g. "0 */6 * * *" — no macros or day/month names). Only valid when the target workload is type "cron".
capacityAINoEnable or disable spec.defaultOptions.capacityAI — applies to every type (default ON for serverless/standard/cron; on cron the new reservation takes effect at the next scheduled run). Explicit true is rejected with the cpu metric and with GPUs.
containersNoOptional container patches, merged by required `name` into existing containers. Minimal patch item is { "name": "app" }; other containers are preserved. Set only fields you want to change. An unknown name ADDS a new container and must include image.
autoscalingNoAutoscaling patch → merged key-by-key into spec.defaultOptions.autoscaling.
descriptionNoUpdate workload description
historyLimitNoNumber of completed job instances to retain (default 5)
identityLinkNoIdentity the workload runs as, for cloud and secret access, e.g. //identity/my-id. For a secret, grant_workload_secret_access sets it.
removeTagKeysNoTag keys to remove from the resource.
restartPolicyNoWhat to do when a job instance fails
firewallConfigNoReplace the firewall config wholesale.
timeoutSecondsNoSet spec.defaultOptions.timeoutSeconds — max request duration (platform default 5s; serverless caps at 600)
concurrencyPolicyNoWhat to do when a run is due while a prior run is still active (default Forbid)
removeIdentityLinkNotrue deletes spec.identityLink, revoking the cloud/secret access it granted.
supportDynamicTagsNoEnable or disable spec.supportDynamicTags (detects image digest changes)
activeDeadlineSecondsNoMax seconds to wait for the job to complete before it is stopped

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okYes
dataNoThe full result. Read this, not only the summary.
detailsNo
summaryYes
nextStepsNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed96 schema fields changed
    • removedInput schema / $schema
      Removed value: -"http://json-schema.org/draft-07/schema#"
    • removedInput schema / additionalProperties
      Removed value: -false
    • removedInput schema / properties / autoscaling / additionalProperties
      Removed value: -false
    • removedInput schema / properties / autoscaling / properties / keda / additionalProperties
      Removed value: -false
    • changedInput schema / properties / autoscaling / properties / keda / description
      Previous value: -"KEDA scaling configuration (use with metric=\"keda\"; standard/stateful only). The GVC must enable KEDA FIRST — update_gvc with spec.keda.enabled: true. Trigger auth secrets are listed in the GVC spec.keda.secrets and referenced via authenticationRef.name. When a trigger source is itself a Control Plane workload, that workload's internal firewall must allow cpln://internal/keda in inboundAllowWorkload."New value: +"For metric keda on standard or stateful. The GVC needs spec.keda.enabled first (update_gvc); trigger auth secrets are listed in its spec.keda.secrets. A workload used as a trigger source must admit cpln://internal/keda. Shape: {triggers: [{type, metadata, name, metricType, authenticationRef: {name}}], advanced, fallback, pollingInterval, cooldownPeriod}."
    • removedInput schema / properties / autoscaling / properties / keda / properties
      Removed value: -{
      -  "advanced": {
      -    "additionalProperties": false,
      -    "properties": {
      -      "scalingModifiers": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "activationTarget": {
      -            "description": "New activation target value for the composed metric",
      -            "type": "string"
      -          },
      -          "formula": {
      -            "description": "Formula composing metrics together (mathematical/conditional statements)",
      -            "type": "string"
      -          },
      -          "metricType": {
      -            "enum": [
      -              "AverageValue",
      -              "Value",
      -              "Utilization"
      -            ],
      -            "type": "string"
      -          },
      -          "target": {
      -            "description": "New target value for the composed metric",
      -            "type": "string"
      -          }
      -        },
      -        "type": "object"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "cooldownPeriod": {
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "fallback": {
      -    "additionalProperties": false,
      -    "properties": {
      -      "behavior": {
      -        "enum": [
      -          "static",
      -          "currentReplicas",
      -          "currentReplicasIfHigher",
      -          "currentReplicasIfLower"
      -        ],
      -        "type": "string"
      -      },
      -      "failureThreshold": {
      -        "description": "Consecutive failures required to trigger fallback",
      -        "type": "integer"
      -      },
      -      "replicas": {
      -        "description": "Replica count to scale to when fallback triggers",
      -        "type": "integer"
      -      }
      -    },
      -    "required": [
      -      "failureThreshold",
      -      "replicas"
      -    ],
      -    "type": "object"
      -  },
      -  "initialCooldownPeriod": {
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "pollingInterval": {
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "triggers": {
      -    "description": "KEDA triggers used for scaling",
      -    "items": {
      -      "additionalProperties": false,
      -      "properties": {
      -        "authenticationRef": {
      -          "additionalProperties": false,
      -          "properties": {
      -            "name": {
      -              "description": "Name of a secret listed in the GVC spec.keda.secrets",
      -              "minLength": 1,
      -              "type": "string"
      -            }
      -          },
      -          "required": [
      -            "name"
      -          ],
      -          "type": "object"
      -        },
      -        "metadata": {
      -          "additionalProperties": {
      -            "type": "string"
      -          },
      -          "description": "Trigger configuration parameters",
      -          "type": "object"
      -        },
      -        "metricType": {
      -          "description": "Metric type used for scaling",
      -          "enum": [
      -            "AverageValue",
      -            "Value",
      -            "Utilization"
      -          ],
      -          "type": "string"
      -        },
      -        "name": {
      -          "description": "Optional trigger name",
      -          "type": "string"
      -        },
      -        "type": {
      -          "description": "KEDA trigger type, e.g. \"prometheus\", \"aws-sqs\"",
      -          "minLength": 1,
      -          "type": "string"
      -        },
      -        "useCachedMetrics": {
      -          "description": "Cache metric values during the polling interval",
      -          "type": "boolean"
      -        }
      -      },
      -      "required": [
      -        "type"
      -      ],
      -      "type": "object"
      -    },
      -    "type": "array"
      -  }
      -}
    • changedInput schema / properties / autoscaling / properties / metric / description
      Previous value: -"Single scaling metric (mutually exclusive with multi). Allowed values depend on the workload TYPE: serverless → concurrency, cpu, memory, rps, disabled; standard/stateful → cpu, memory, latency, rps, keda, disabled. concurrency is serverless-ONLY; latency, keda, and multi are standard/stateful-only. Omitted → serverless defaults to concurrency; standard/stateful default to cpu — and the cpu default silently disables Capacity AI. Choose the metric that matches the workload type and its traffic shape (rps/concurrency for HTTP, cpu/memory for compute)."New value: +"Single metric, exclusive with multi. serverless: concurrency (default), cpu, memory, rps, disabled. standard and stateful: cpu (turns Capacity AI off), memory, latency, rps, keda, disabled. Omitted on standard with Capacity AI on, it is disabled, which holds minScale replicas. rps or concurrency for HTTP, cpu or memory for compute."
    • removedInput schema / properties / autoscaling / properties / multi / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / autoscaling / properties / multi / minItems
      Removed value: -1
    • removedInput schema / properties / containers / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / command / maxLength
      Removed value: -256
    • removedInput schema / properties / containers / items / properties / cpu / maxLength
      Removed value: -20
    • removedInput schema / properties / containers / items / properties / cpu / pattern
      Removed value: -"^([0-9]+)(m|(\\.[0-9]{1,3}))?$"
    • changedInput schema / properties / containers / items / properties / env / description
      Previous value: -"Optional environment variables for this container. Omit to leave unset."New value: +"Optional environment variables for this container. Omit to leave unset. Grant access to each referenced secret with grant_workload_secret_access."
    • removedInput schema / properties / containers / items / properties / env / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / env / items / properties / name / maxLength
      Removed value: -120
    • removedInput schema / properties / containers / items / properties / env / items / properties / name / minLength
      Removed value: -1
    • removedInput schema / properties / containers / items / properties / env / items / properties / name / pattern
      Removed value: -"^[-._a-zA-Z][-._a-zA-Z0-9]*$"
    • changedInput schema / properties / containers / items / properties / env / items / properties / value / description
      Previous value: -"Literal value, or a secret reference like cpln://secret/<name>.<key>. Secret refs require the workload identity to have reveal permission or the deployment PAUSES — after create_workload, grant it with grant_workload_secret_access."New value: +"Non-sensitive literal value, or a secret reference like cpln://secret/<name>.<key>. Never send passwords, API keys, or tokens. The workload identity needs reveal permission on a referenced secret, or the deployment PAUSES."
    • removedInput schema / properties / containers / items / properties / env / items / properties / value / maxLength
      Removed value: -4096
    • removedInput schema / properties / containers / items / properties / gpu / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / gpu / properties
      Removed value: -{
      -  "custom": {
      -    "additionalProperties": false,
      -    "description": "Custom (non-NVIDIA) GPU resource specification",
      -    "properties": {
      -      "quantity": {
      -        "description": "Number of custom GPUs to allocate (default 1)",
      -        "maximum": 8,
      -        "minimum": 0,
      -        "type": "number"
      -      },
      -      "resource": {
      -        "description": "Custom GPU resource name (e.g., amd.com/gpu)",
      -        "maxLength": 64,
      -        "pattern": "^[a-zA-Z0-9./_-]*$",
      -        "type": "string"
      -      },
      -      "runtimeClass": {
      -        "description": "Runtime class for the custom GPU",
      -        "maxLength": 64,
      -        "pattern": "^[a-zA-Z0-9./]*$",
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "resource"
      -    ],
      -    "type": "object"
      -  },
      -  "nvidia": {
      -    "additionalProperties": false,
      -    "description": "NVIDIA GPU resource specification",
      -    "properties": {
      -      "model": {
      -        "description": "NVIDIA GPU model",
      -        "enum": [
      -          "t4",
      -          "a10g"
      -        ],
      -        "type": "string"
      -      },
      -      "quantity": {
      -        "description": "Number of NVIDIA GPUs to allocate (default 1)",
      -        "maximum": 4,
      -        "minimum": 0,
      -        "type": "number"
      -      }
      -    },
      -    "required": [
      -      "model"
      -    ],
      -    "type": "object"
      -  }
      -}
    • changedInput schema / properties / containers / items / properties / image / description
      Previous value: -"Image reference (required): org-internal = //image/NAME:TAG (long form /org/<org>/image/NAME:TAG also valid; no pull secret needed); public Docker Hub = bare (nginx:latest, never docker.io/...); other registries = exact host path — PRIVATE external registries need a pull secret on the GVC (docker, ecr, or gcp secret types only). Must be linux/amd64."New value: +"Image: //image/NAME:TAG for this org, or an exact external reference. A private external registry needs a docker, ecr, or gcp pull secret on the GVC."
    • removedInput schema / properties / containers / items / properties / image / minLength
      Removed value: -1
    • removedInput schema / properties / containers / items / properties / lifecycle / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / lifecycle / properties
      Removed value: -{
      -  "postStart": {
      -    "additionalProperties": false,
      -    "description": "Action to perform after the container starts",
      -    "properties": {
      -      "exec": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "command": {
      -            "description": "Command run immediately after the container starts",
      -            "items": {
      -              "type": "string"
      -            },
      -            "type": "array"
      -          }
      -        },
      -        "required": [
      -          "command"
      -        ],
      -        "type": "object"
      -      }
      -    },
      -    "required": [
      -      "exec"
      -    ],
      -    "type": "object"
      -  },
      -  "preStop": {
      -    "additionalProperties": false,
      -    "description": "Action to perform before the container stops. When omitted the platform runs a default preStop of sh -c \"sleep N\" — an image without sleep (e.g. distroless) or a custom preStop that fails causes ALL containers in the replica to be SIGKILLed immediately.",
      -    "properties": {
      -      "exec": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "command": {
      -            "description": "Command run immediately before the container stops",
      -            "items": {
      -              "type": "string"
      -            },
      -            "type": "array"
      -          }
      -        },
      -        "required": [
      -          "command"
      -        ],
      -        "type": "object"
      -      }
      -    },
      -    "required": [
      -      "exec"
      -    ],
      -    "type": "object"
      -  }
      -}
    • removedInput schema / properties / containers / items / properties / livenessProbe / additionalProperties
      Removed value: -false
    • changedInput schema / properties / containers / items / properties / livenessProbe / description
      Previous value: -"Optional probe that restarts the container when it fails. If present, set exactly one handler."New value: +"Optional probe that restarts the container when it fails."
    • removedInput schema / properties / containers / items / properties / livenessProbe / properties
      Removed value: -{
      -  "exec": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: execute a command to check health (exit 0 = healthy). Use exactly one handler total.",
      -    "properties": {
      -      "command": {
      -        "description": "Command to execute for the health check",
      -        "items": {
      -          "type": "string"
      -        },
      -        "minItems": 1,
      -        "type": "array"
      -      }
      -    },
      -    "required": [
      -      "command"
      -    ],
      -    "type": "object"
      -  },
      -  "failureThreshold": {
      -    "description": "Consecutive failures to be considered failed (default 3)",
      -    "maximum": 20,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "grpc": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform a gRPC health check. Use exactly one handler total.",
      -    "properties": {
      -      "port": {
      -        "description": "Port to perform the gRPC health check on",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      }
      -    },
      -    "required": [
      -      "port"
      -    ],
      -    "type": "object"
      -  },
      -  "httpGet": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform an HTTP GET health check (2xx/3xx = healthy). Use exactly one handler total.",
      -    "properties": {
      -      "httpHeaders": {
      -        "description": "Custom HTTP headers to include in the health check request",
      -        "items": {
      -          "additionalProperties": false,
      -          "properties": {
      -            "name": {
      -              "description": "HTTP header name",
      -              "maxLength": 128,
      -              "type": "string"
      -            },
      -            "value": {
      -              "description": "HTTP header value",
      -              "maxLength": 128,
      -              "type": "string"
      -            }
      -          },
      -          "required": [
      -            "name",
      -            "value"
      -          ],
      -          "type": "object"
      -        },
      -        "type": "array"
      -      },
      -      "path": {
      -        "description": "HTTP path to request (default \"/\")",
      -        "maxLength": 256,
      -        "type": "string"
      -      },
      -      "port": {
      -        "description": "Port to perform the HTTP health check on (defaults to the container port)",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      },
      -      "scheme": {
      -        "description": "HTTP scheme to use (default HTTP)",
      -        "enum": [
      -          "HTTP",
      -          "HTTPS"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "initialDelaySeconds": {
      -    "description": "Seconds to wait before the first check (readiness default 10, liveness default 60)",
      -    "maximum": 600,
      -    "minimum": 0,
      -    "type": "integer"
      -  },
      -  "periodSeconds": {
      -    "description": "How often to perform the check (default 10)",
      -    "maximum": 600,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "successThreshold": {
      -    "description": "Consecutive successes to be considered healthy (default 1)",
      -    "maximum": 20,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "tcpSocket": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform a TCP socket health check. Use exactly one handler total.",
      -    "properties": {
      -      "port": {
      -        "description": "Port to perform the TCP socket check on (defaults to the container port)",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "timeoutSeconds": {
      -    "description": "Seconds after which the check times out (default 1)",
      -    "maximum": 600,
      -    "minimum": 1,
      -    "type": "integer"
      -  }
      -}
    • removedInput schema / properties / containers / items / properties / memory / maxLength
      Removed value: -20
    • removedInput schema / properties / containers / items / properties / memory / pattern
      Removed value: -"^[0-9]+(\\.[0-9]{1,3})?(G|M|k|Gi|Mi|Ki)?$"
    • removedInput schema / properties / containers / items / properties / metrics / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / metrics / properties
      Removed value: -{
      -  "dropMetrics": {
      -    "description": "Drop metrics whose names match these regex patterns",
      -    "items": {
      -      "type": "string"
      -    },
      -    "type": "array"
      -  },
      -  "path": {
      -    "description": "HTTP path where Prometheus metrics are exposed (default /metrics)",
      -    "maxLength": 128,
      -    "type": "string"
      -  },
      -  "port": {
      -    "description": "Port where Prometheus metrics are exposed",
      -    "maximum": 65535,
      -    "minimum": 80,
      -    "type": "integer"
      -  }
      -}
    • removedInput schema / properties / containers / items / properties / metrics / required
      Removed value: -[
      -  "port"
      -]
    • removedInput schema / properties / containers / items / properties / minCpu / maxLength
      Removed value: -20
    • removedInput schema / properties / containers / items / properties / minCpu / pattern
      Removed value: -"^([0-9]+)(m|(\\.[0-9]{1,3}))?$"
    • removedInput schema / properties / containers / items / properties / minMemory / maxLength
      Removed value: -20
    • removedInput schema / properties / containers / items / properties / minMemory / pattern
      Removed value: -"^[0-9]+(\\.[0-9]{1,3})?(G|M|k|Gi|Mi|Ki)?$"
    • removedInput schema / properties / containers / items / properties / name / maxLength
      Removed value: -64
    • removedInput schema / properties / containers / items / properties / name / minLength
      Removed value: -2
    • removedInput schema / properties / containers / items / properties / name / pattern
      Removed value: -"^[a-z][a-z0-9-]*[a-z0-9]$"
    • removedInput schema / properties / containers / items / properties / ports / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / readinessProbe / additionalProperties
      Removed value: -false
    • changedInput schema / properties / containers / items / properties / readinessProbe / description
      Previous value: -"Optional probe that gates whether the container receives traffic. If present, set exactly one handler."New value: +"Optional probe that gates whether the container receives traffic."
    • removedInput schema / properties / containers / items / properties / readinessProbe / properties
      Removed value: -{
      -  "exec": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: execute a command to check health (exit 0 = healthy). Use exactly one handler total.",
      -    "properties": {
      -      "command": {
      -        "description": "Command to execute for the health check",
      -        "items": {
      -          "type": "string"
      -        },
      -        "minItems": 1,
      -        "type": "array"
      -      }
      -    },
      -    "required": [
      -      "command"
      -    ],
      -    "type": "object"
      -  },
      -  "failureThreshold": {
      -    "description": "Consecutive failures to be considered failed (default 3)",
      -    "maximum": 20,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "grpc": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform a gRPC health check. Use exactly one handler total.",
      -    "properties": {
      -      "port": {
      -        "description": "Port to perform the gRPC health check on",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      }
      -    },
      -    "required": [
      -      "port"
      -    ],
      -    "type": "object"
      -  },
      -  "httpGet": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform an HTTP GET health check (2xx/3xx = healthy). Use exactly one handler total.",
      -    "properties": {
      -      "httpHeaders": {
      -        "description": "Custom HTTP headers to include in the health check request",
      -        "items": {
      -          "additionalProperties": false,
      -          "properties": {
      -            "name": {
      -              "description": "HTTP header name",
      -              "maxLength": 128,
      -              "type": "string"
      -            },
      -            "value": {
      -              "description": "HTTP header value",
      -              "maxLength": 128,
      -              "type": "string"
      -            }
      -          },
      -          "required": [
      -            "name",
      -            "value"
      -          ],
      -          "type": "object"
      -        },
      -        "type": "array"
      -      },
      -      "path": {
      -        "description": "HTTP path to request (default \"/\")",
      -        "maxLength": 256,
      -        "type": "string"
      -      },
      -      "port": {
      -        "description": "Port to perform the HTTP health check on (defaults to the container port)",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      },
      -      "scheme": {
      -        "description": "HTTP scheme to use (default HTTP)",
      -        "enum": [
      -          "HTTP",
      -          "HTTPS"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "initialDelaySeconds": {
      -    "description": "Seconds to wait before the first check (readiness default 10, liveness default 60)",
      -    "maximum": 600,
      -    "minimum": 0,
      -    "type": "integer"
      -  },
      -  "periodSeconds": {
      -    "description": "How often to perform the check (default 10)",
      -    "maximum": 600,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "successThreshold": {
      -    "description": "Consecutive successes to be considered healthy (default 1)",
      -    "maximum": 20,
      -    "minimum": 1,
      -    "type": "integer"
      -  },
      -  "tcpSocket": {
      -    "additionalProperties": false,
      -    "description": "Optional probe handler: perform a TCP socket health check. Use exactly one handler total.",
      -    "properties": {
      -      "port": {
      -        "description": "Port to perform the TCP socket check on (defaults to the container port)",
      -        "maximum": 65535,
      -        "minimum": 80,
      -        "type": "integer"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "timeoutSeconds": {
      -    "description": "Seconds after which the check times out (default 1)",
      -    "maximum": 600,
      -    "minimum": 1,
      -    "type": "integer"
      -  }
      -}
    • removedInput schema / properties / containers / items / properties / removeEnvNames / items / minLength
      Removed value: -1
    • changedInput schema / properties / containers / items / properties / volumes / description
      Previous value: -"Volume mounts for this container"New value: +"Volume mounts for this container."
    • removedInput schema / properties / containers / items / properties / volumes / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / containers / items / properties / volumes / items / description
      Removed value: -"Mount an object store bucket, volume set, secret, or scratch volume into the container"
    • removedInput schema / properties / containers / items / properties / volumes / items / properties
      Removed value: -{
      -  "path": {
      -    "description": "Absolute mount path inside the container (required for non-vm workloads). /tmp, /var, /dev are reserved.",
      -    "minLength": 1,
      -    "type": "string"
      -  },
      -  "recoveryPolicy": {
      -    "description": "For persistent volumes: retain (default) or recycle existing data on replica creation",
      -    "enum": [
      -      "retain",
      -      "recycle"
      -    ],
      -    "type": "string"
      -  },
      -  "uri": {
      -    "description": "Volume source URI: s3://bucket, gs://bucket, azureblob://account/container, azurefs://account/share, cpln://volumeset/<name>, cpln://secret/<name>, or scratch://<name>.",
      -    "minLength": 1,
      -    "pattern": "^(s3|gs|azureblob|azurefs|cpln|scratch|k8s):\\/\\/.+",
      -    "type": "string"
      -  }
      -}
    • removedInput schema / properties / containers / items / properties / volumes / items / required
      Removed value: -[
      -  "uri",
      -  "path"
      -]
    • removedInput schema / properties / containers / items / properties / volumes / maxItems
      Removed value: -15
    • removedInput schema / properties / containers / items / properties / workingDir / maxLength
      Removed value: -128
    • removedInput schema / properties / containers / maxItems
      Removed value: -8
    • removedInput schema / properties / containers / minItems
      Removed value: -1
    • removedInput schema / properties / firewallConfig / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / external / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / external / properties / http / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / external / properties / http / properties / inboundHeaderFilter / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / external / properties / http / properties / inboundHeaderFilter / items / properties / key / maxLength
      Removed value: -128
    • removedInput schema / properties / firewallConfig / properties / external / properties / inboundAllowCIDR / maxItems
      Removed value: -250
    • removedInput schema / properties / firewallConfig / properties / external / properties / outboundAllowHostname / items / maxLength
      Removed value: -128
    • removedInput schema / properties / firewallConfig / properties / external / properties / outboundAllowHostname / items / pattern
      Removed value: -"^(?![0-9]+$)(?!.*-$)([*]?)(?!-)[a-z0-9-.]+$"
    • removedInput schema / properties / firewallConfig / properties / external / properties / outboundAllowPort / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / internal / additionalProperties
      Removed value: -false
    • removedInput schema / properties / firewallConfig / properties / internal / properties / inboundAllowWorkload / items / maxLength
      Removed value: -256
    • removedInput schema / properties / firewallConfig / properties / internal / properties / inboundAllowWorkload / items / minLength
      Removed value: -1
    • changedInput schema / properties / gvc / description
      Previous value: -"GVC slug (lowercase kebab-case). Use the GVC the user named; otherwise discover with list_resources (kind=\"gvc\") and let them choose — never guess (a wrong GVC targets the wrong environment)."New value: +"GVC slug. If the user named none, list_resources (kind \"gvc\") and let them choose."
    • removedInput schema / properties / gvc / maxLength
      Removed value: -63
    • removedInput schema / properties / gvc / minLength
      Removed value: -1
    • removedInput schema / properties / gvc / pattern
      Removed value: -"^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$"
    • changedInput schema / properties / identityLink / description
      Previous value: -"Identity link granting 3rd-party cloud resource access, e.g. //identity/my-id"New value: +"Identity the workload runs as, for cloud and secret access, e.g. //identity/my-id. For a secret, grant_workload_secret_access sets it."
    • removedInput schema / properties / identityLink / maxLength
      Removed value: -256
    • removedInput schema / properties / identityLink / minLength
      Removed value: -1
    • removedInput schema / properties / identityLink / pattern
      Removed value: -"^(\\/org\\/[^/]+\\/.+|\\/\\/.+)$"
    • changedInput schema / properties / name / description
      Previous value: -"Workload name (lowercase kebab-case, must start with a letter, max 49 chars, cannot end with -headless). The name is IMMUTABLE — \"renaming\" requires delete + recreate (loses public URL, internal DNS, policy targetLinks)."New value: +"Workload name. Immutable: renaming is delete and recreate, which loses the URL and internal DNS."
    • removedInput schema / properties / name / maxLength
      Removed value: -49
    • removedInput schema / properties / name / minLength
      Removed value: -2
    • removedInput schema / properties / name / pattern
      Removed value: -"^[a-z]([-a-z0-9])*[a-z0-9]$"
    • changedInput schema / properties / org / description
      Previous value: -"Organization slug (lowercase kebab-case). NEVER guess — if the user has not named one, ask. On org-not-found, stop and ask; do not retry variants."New value: +"Organization slug."
    • removedInput schema / properties / org / maxLength
      Removed value: -63
    • removedInput schema / properties / org / minLength
      Removed value: -1
    • removedInput schema / properties / org / pattern
      Removed value: -"^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$"
    • removedInput schema / properties / removeTagKeys / items / minLength
      Removed value: -1
    • removedInput schema / properties / schedule / minLength
      Removed value: -1
    • removedInput schema / properties / tags / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / tags / items / properties / key / minLength
      Removed value: -1
    • removedInput schema / properties / tags / maxItems
      Removed value: -50
    • changedInput schema / required
      Previous value: -[
      -  "org",
      -  "gvc",
      -  "name"
      -]New value: +[
      +  "gvc",
      +  "name"
      +]
    • removedOutput schema / $schema
      Removed value: -"http://json-schema.org/draft-07/schema#"
    • removedOutput schema / additionalProperties
      Removed value: -false
    • changedOutput schema / properties / data / description
      Previous value: -"The full machine-readable result — list rows, the resource object, query results. Read THIS, not just the summary."New value: +"The full result. Read this, not only the summary."
    • addedOutput schema / properties / details
      Added value: +{
      +  "type": "string"
      +}
    • removedOutput schema / properties / nextSteps / description
      Removed value: -"Recommended follow-up actions for this task, in order."
    • removedOutput schema / properties / ok / description
      Removed value: -"Whether the call succeeded."
    • removedOutput schema / properties / summary / description
      Removed value: -"One-line summary of the result."
  2. Changed5 schema fields changed
    • changedInput schema / properties / capacityAI / description
      Previous value: -"Enable or disable spec.defaultOptions.capacityAI (default ON for serverless/standard, stripped on stateful/cron; explicit true is rejected with the cpu metric and with GPUs). Not valid for a cron workload."New value: +"Enable or disable spec.defaultOptions.capacityAI — applies to every type (default ON for serverless/standard/cron; on cron the new reservation takes effect at the next scheduled run). Explicit true is rejected with the cpu metric and with GPUs."
    • changedInput schema / properties / containers / items / properties / gpu / properties / custom / properties / resource / pattern
      Previous value: -"^[a-zA-Z0-9./]*$"New value: +"^[a-zA-Z0-9./_-]*$"
    • addedInput schema / properties / containers / items / properties / removeLivenessProbe
      Added value: +{
      +  "description": "true deletes the livenessProbe on this container.",
      +  "type": "boolean"
      +}
    • addedInput schema / properties / containers / items / properties / removeReadinessProbe
      Added value: +{
      +  "description": "true deletes the readinessProbe on this container.",
      +  "type": "boolean"
      +}
    • addedInput schema / properties / removeIdentityLink
      Added value: +{
      +  "description": "true deletes spec.identityLink, revoking the cloud/secret access it granted.",
      +  "type": "boolean"
      +}
  3. Changed1 schema field changed
    • changedInput schema / properties / containers / items / properties / env / items / properties / value / description
      Previous value: -"Literal value, or a secret reference like cpln://secret/<name>.<key>. Secret refs require the workload identity to have reveal permission or the deployment PAUSES — after create_workload, grant it with workload_reveal_secret."New value: +"Literal value, or a secret reference like cpln://secret/<name>.<key>. Secret refs require the workload identity to have reveal permission or the deployment PAUSES — after create_workload, grant it with grant_workload_secret_access."
  4. First observed

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true, idempotentHint=true, openWorldHint=true, readOnlyHint=false. The description adds real context beyond that: type/name immutability, the PATCH merge semantics ('only the fields passed change'), and the warning that downgrading probes/autoscaling can break workloads. It doesn't explicitly warn about the destructive potential in the same terms, but it clearly signals reversibility concerns and points to get_resource for rollback.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action (update workload, PATCH semantics), then immediately the immutability constraints, then type-specifics, then safety, then alternatives. Every sentence carries a distinct constraint or routing instruction. Might border on dense but no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Output schema exists, so return values needn't be explained. For a 22-parameter, nested-object mutation tool with rich annotations, the description covers scope, immutability, type-conditional fields, container merge semantics, and safety. It leaves some nuance to the schema (as appropriate) but does not leave the agent without the critical operational constraints.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so baseline is 3. However, the description goes beyond the schema by surfacing cross-type field validity rules — cron takes schedule/job policy/suspend/capacityAI/containers but not autoscaling/timeoutSeconds/debug, and schedule/job fields are rejected on other types. That is merge/validation semantics not stated identically in any single schema field. It also notes containers merge by name.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb+resource ('Update a workload') and immediately clarifies the PATCH semantics. More importantly, it carves out the boundaries explicitly: type and name are immutable, cron-specific fields are only for cron types, and it routes loadBalancer/sidecar/extras/localOptions/rolloutOptions/securityOptions/requestRetryPolicy to their own configure_workload_* tools. An agent can distinguish this from update_gvc, deploy_app, configure_workload_* and create_workload without opening schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit when-to-use guidance: 'Read it with get_resource first so a rollback exists', 'never downgrade probes or autoscaling silently', and a direct alternative named for the app-image/exposure case ('A new image or exposure for an app: deploy_app'). It also names what is NOT handled here (loadBalancer, sidecar, etc. → configure_workload_*). This is a genuine routing guide, not just context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.