Skip to content
Proud to collaborate with Microsoft for Startups

cloudflare.pages.bind-cloud-run-backend ​

One call: wire a private GCP Cloud Run backend to a Cloudflare Pages /api gateway. Ensures a scoped invoker service account, grants it run.invoker, mints a JSON key, and sets it as the Pages GCP_SA_KEY secret plus the CLOUD_RUN_URL env var — no gcloud, no dashboard.

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-cloudflare
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Organization UUID.
gcp_connection_uuiduuidYes—GCP connection with access to the backend project.
cloud_run_servicestringYes—Cloud Run service name, e.g. calendar.
regionstringYes—Cloud Run region, e.g. us-central1.
cloud_run_urlstringNo—Backend URL for the CLOUD_RUN_URL env var. Optional input but required at run time — not derived from the service name.
gcp_projectstringNo—Backend GCP project id; defaults from the GCP connection / the minted service account email.
cloudflare_connection_uuiduuidYes—Cloudflare connection owning the Pages project.
pages_project_namestringYes—Target Pages project, e.g. senai-calendar-shadow.
invoker_accountstringNo—Invoker service-account short id to create/reuse; default '<pages_project>-invoker' (sanitized/truncated to GCP limits).
secret_namestringNo—Pages secret name for the minted key; default 'GCP_SA_KEY'.
env_namestringNo—Pages env var name for the backend URL; default 'CLOUD_RUN_URL'.
redeploybooleanNo—Trigger cloudflare.pages.build-and-deploy after wiring so Pages Functions bind the new env/secret; default false.

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Organization UUID.
gcp_connection_uuiduuidYes—GCP connection with access to the backend project.
cloud_run_servicestringYes—Cloud Run service name, e.g. calendar.
regionstringYes—Cloud Run region, e.g. us-central1.
cloud_run_urlstringNo—Backend URL for the CLOUD_RUN_URL env var. Optional input but required at run time — not derived from the service name.
gcp_projectstringNo—Backend GCP project id; defaults from the GCP connection / the minted service account email.
cloudflare_connection_uuiduuidYes—Cloudflare connection owning the Pages project.
pages_project_namestringYes—Target Pages project, e.g. senai-calendar-shadow.
invoker_accountstringNo—Invoker service-account short id to create/reuse; default '<pages_project>-invoker' (sanitized/truncated to GCP limits).
secret_namestringNo—Pages secret name for the minted key; default 'GCP_SA_KEY'.
env_namestringNo—Pages env var name for the backend URL; default 'CLOUD_RUN_URL'.
redeploybooleanNo—Trigger cloudflare.pages.build-and-deploy after wiring so Pages Functions bind the new env/secret; default false.
account_emailstringNo—Email of the ensured invoker service account.
key_namestringNo—Resource name of the minted SA key (for rotation/cleanup); the key material itself is never persisted.
secret_setbooleanNo—True once the Pages secret was set from the minted key.
env_setbooleanNo—True once the Pages CLOUD_RUN_URL env var was set.
deploy_workflow_uuidstringNo—cloudflare.pages.build-and-deploy child id (when redeploy=true).
statusstringNo—Overall status ('bound' once wiring completes).
granted_atstringNo—ISO8601 timestamp when the invoker SA + binding were ensured.
wired_atstringNo—ISO8601 timestamp when the Pages secret + env were set.
completed_atstringNo—ISO8601 timestamp when the workflow completed.
_children_by_keydictNo—Child workflow ids keyed by 'deploy' (redeploy path only).
failure_reasonstringNo—Engine-stamped human-readable failure reason
failed_at_statestringNo—Engine-stamped state when the workflow failed
failed_stepstringNo—Engine-stamped step name (DAG path)
failed_layerintegerNo—Engine-stamped layer index (DAG path)
errorstringNo—Engine-stamped exception message
error_typestringNo—Engine-stamped exception class name
failure_typestringNo—Engine-stamped failure category (atomic path)
failed_actionstringNo—Engine-stamped action method that raised (atomic path)

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—ensure_invokerBind request accepted
grantedNoNo—wire_pagesInvoker SA ensured + run.invoker granted
wiredNoNo—finalizePages secret + env set from the minted key
completedNoYesYes—Cloud Run backend bound to the Pages project
failedNoYesNo—Binding failed

State Diagram ​

Transitions ​

FromActionToDescription
pendingensure_invokergranted—
grantedwire_pageswired—
wiredfinalizecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "cloudflare.pages.bind-cloud-run-backend",
  "initial_data": {
    "organization_uuid": "value",
    "gcp_connection_uuid": "value",
    "cloud_run_service": "value",
    "region": "value"
  }
}