cloudflare.pages.bind-cloud-run-backend
One call: wire a private GCP Cloud Run backend to a Cloudflare Pages /api gateway. Ensures a scoped invoker service account, grants it run.invoker, mints a JSON key, and sets it as the Pages GCP_SA_KEY secret plus the CLOUD_RUN_URL env var — no gcloud, no dashboard.
Overview
| Property | Value |
|---|---|
| Workflow type | Linear |
| Library | App-cloudflare |
| Version | 1.0 |
Input Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Organization UUID. |
gcp_connection_uuid | uuid | Yes | — | GCP connection with access to the backend project. |
cloud_run_service | string | Yes | — | Cloud Run service name, e.g. calendar. |
region | string | Yes | — | Cloud Run region, e.g. us-central1. |
cloud_run_url | string | No | — | Backend URL for the CLOUD_RUN_URL env var. Optional input but required at run time — not derived from the service name. |
gcp_project | string | No | — | Backend GCP project id; defaults from the GCP connection / the minted service account email. |
cloudflare_connection_uuid | uuid | Yes | — | Cloudflare connection owning the Pages project. |
pages_project_name | string | Yes | — | Target Pages project, e.g. senai-calendar-shadow. |
invoker_account | string | No | — | Invoker service-account short id to create/reuse; default '<pages_project>-invoker' (sanitized/truncated to GCP limits). |
secret_name | string | No | — | Pages secret name for the minted key; default 'GCP_SA_KEY'. |
env_name | string | No | — | Pages env var name for the backend URL; default 'CLOUD_RUN_URL'. |
redeploy | boolean | No | — | Trigger cloudflare.pages.build-and-deploy after wiring so Pages Functions bind the new env/secret; default false. |
Output Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Organization UUID. |
gcp_connection_uuid | uuid | Yes | — | GCP connection with access to the backend project. |
cloud_run_service | string | Yes | — | Cloud Run service name, e.g. calendar. |
region | string | Yes | — | Cloud Run region, e.g. us-central1. |
cloud_run_url | string | No | — | Backend URL for the CLOUD_RUN_URL env var. Optional input but required at run time — not derived from the service name. |
gcp_project | string | No | — | Backend GCP project id; defaults from the GCP connection / the minted service account email. |
cloudflare_connection_uuid | uuid | Yes | — | Cloudflare connection owning the Pages project. |
pages_project_name | string | Yes | — | Target Pages project, e.g. senai-calendar-shadow. |
invoker_account | string | No | — | Invoker service-account short id to create/reuse; default '<pages_project>-invoker' (sanitized/truncated to GCP limits). |
secret_name | string | No | — | Pages secret name for the minted key; default 'GCP_SA_KEY'. |
env_name | string | No | — | Pages env var name for the backend URL; default 'CLOUD_RUN_URL'. |
redeploy | boolean | No | — | Trigger cloudflare.pages.build-and-deploy after wiring so Pages Functions bind the new env/secret; default false. |
account_email | string | No | — | Email of the ensured invoker service account. |
key_name | string | No | — | Resource name of the minted SA key (for rotation/cleanup); the key material itself is never persisted. |
secret_set | boolean | No | — | True once the Pages secret was set from the minted key. |
env_set | boolean | No | — | True once the Pages CLOUD_RUN_URL env var was set. |
deploy_workflow_uuid | string | No | — | cloudflare.pages.build-and-deploy child id (when redeploy=true). |
status | string | No | — | Overall status ('bound' once wiring completes). |
granted_at | string | No | — | ISO8601 timestamp when the invoker SA + binding were ensured. |
wired_at | string | No | — | ISO8601 timestamp when the Pages secret + env were set. |
completed_at | string | No | — | ISO8601 timestamp when the workflow completed. |
_children_by_key | dict | No | — | Child workflow ids keyed by 'deploy' (redeploy path only). |
failure_reason | string | No | — | Engine-stamped human-readable failure reason |
failed_at_state | string | No | — | Engine-stamped state when the workflow failed |
failed_step | string | No | — | Engine-stamped step name (DAG path) |
failed_layer | integer | No | — | Engine-stamped layer index (DAG path) |
error | string | No | — | Engine-stamped exception message |
error_type | string | No | — | Engine-stamped exception class name |
failure_type | string | No | — | Engine-stamped failure category (atomic path) |
failed_action | string | No | — | Engine-stamped action method that raised (atomic path) |
States
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | ensure_invoker | Bind request accepted |
granted | No | No | — | wire_pages | Invoker SA ensured + run.invoker granted |
wired | No | No | — | finalize | Pages secret + env set from the minted key |
completed | No | Yes | Yes | — | Cloud Run backend bound to the Pages project |
failed | No | Yes | No | — | Binding failed |
State Diagram
Transitions
| From | Action | To | Description |
|---|---|---|---|
pending | ensure_invoker | granted | — |
granted | wire_pages | wired | — |
wired | finalize | completed | — |
* (any state) | fail | failed | — |
API Usage
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "cloudflare.pages.bind-cloud-run-backend",
"initial_data": {
"organization_uuid": "value",
"gcp_connection_uuid": "value",
"cloud_run_service": "value",
"region": "value"
}
}