Skip to main content

run_grants

Token grants the pod holds on behalf of background DAG child processes.

A background DAG run executes in a subprocess Prefect launches from a served deployment, so it inherits nothing from the pod: no Hub session, and on the desktop path no way to reach the orchestrator's token queue, since the queue handle cannot travel as a JSON deployment parameter. Nor can a bearer token travel that way — deployment parameters are persisted in the Prefect database in clear.

The pod therefore mints a nonce per lineage, leaves it in the cache for the child to find (cache.types.background_run_grants), and registers it here. The child presents it to the pod control server's child-config endpoint, which answers with a real token.

Held in memory rather than persisted on purpose. A grant is only meaningful while this pod is alive to honour it, and every run a grant could belong to dies with the pod — so forgetting them on restart is exactly right, and it keeps one copy of the credential off disk.