gcp.compute.ssl_certificate.ensure ​
Ensure a global Google-managed compute sslCertificate (self-link consumable by a target HTTPS proxy) for a domain.
Ensure a global Google-MANAGED compute sslCertificate for a domain.
This is the missing end-to-end HTTPS certificate path for the GCP L7 load balancer. It provisions a Google-managed cert as a computesslCertificate resource whose selfLink a target HTTPS proxy binds directly — unlike gcp.certificates.request, which makes a Certificate Manager cert (returns a certificate_id, NOT a compute sslCertificate self-link the LB path can consume).
Idempotent GET-or-create: an already-present cert of the same name is returned untouched (no re-POST).
IMPORTANT — provisioning latency: a Google-managed cert only turns ACTIVE after the domain's DNS points at the load balancer's serving IP and Google finishes provisioning it, which typically takes ~15-60 minutes. This workflow returns as soon as the resource exists; the returned self_link is immediately bindable by a target HTTPS proxy, but managed_status will read PROVISIONING until Google completes issuance. HTTPS on the LB only serves valid certs once the cert is ACTIVE.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Linear |
| Library | Base-gcp |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
connection_uuid | uuid | Yes | — | GCP CloudConnection UUID. |
project_id | string | No | — | Explicit GCP project override. |
name | string | Yes | — | Compute sslCertificate name. |
domains | list | Yes | — | Domains the managed cert covers (non-empty list). |
description | string | No | — | Optional resource description. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
connection_uuid | uuid | No | — | Echoed connection UUID. |
project_id | string | No | — | Resolved GCP project. |
name | string | No | — | Compute sslCertificate name. |
domains | list | No | — | Domains the managed cert covers. |
description | string | No | — | Resource description. |
self_link | string | No | — | Self link of the sslCertificate (bind this on the target HTTPS proxy). |
operation_name | string | No | — | Compute operation name when created. |
managed_status | string | No | — | Managed cert status (e.g. PROVISIONING/ACTIVE) when known. |
created | boolean | No | — | True when created this run. |
ssl_certificate | json | No | — | Sanitized provider sslCertificate or operation. |
failure_reason | string | No | — | Human-readable failure reason. |
failed_step | string | No | — | Failed logical step. |
failed_layer | json | No | — | Engine failed layer if applicable. |
failed_at_state | string | No | — | State where failure occurred. |
error | string | No | — | Error message. |
error_type | string | No | — | Error class. |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | preflight | — |
creating | No | No | — | complete | — |
preflighting | No | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | preflight | preflighting | — |
preflighting | execute | creating | — |
creating | complete | completed | — |
* (any state) | fail | failed | — |
API Usage ​
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "gcp.compute.ssl_certificate.ensure",
"initial_data": {
"connection_uuid": "value",
"name": "value",
"domains": "value"
}
}