Skip to content
Proud to collaborate with Microsoft for Startups

gcp.compute.ssl_certificate.ensure ​

Ensure a global Google-managed compute sslCertificate (self-link consumable by a target HTTPS proxy) for a domain.

Ensure a global Google-MANAGED compute sslCertificate for a domain.

This is the missing end-to-end HTTPS certificate path for the GCP L7 load balancer. It provisions a Google-managed cert as a computesslCertificate resource whose selfLink a target HTTPS proxy binds directly — unlike gcp.certificates.request, which makes a Certificate Manager cert (returns a certificate_id, NOT a compute sslCertificate self-link the LB path can consume).

Idempotent GET-or-create: an already-present cert of the same name is returned untouched (no re-POST).

IMPORTANT — provisioning latency: a Google-managed cert only turns ACTIVE after the domain's DNS points at the load balancer's serving IP and Google finishes provisioning it, which typically takes ~15-60 minutes. This workflow returns as soon as the resource exists; the returned self_link is immediately bindable by a target HTTPS proxy, but managed_status will read PROVISIONING until Google completes issuance. HTTPS on the LB only serves valid certs once the cert is ACTIVE.

Overview ​

PropertyValue
Workflow typeLinear
LibraryBase-gcp
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidYes—GCP CloudConnection UUID.
project_idstringNo—Explicit GCP project override.
namestringYes—Compute sslCertificate name.
domainslistYes—Domains the managed cert covers (non-empty list).
descriptionstringNo—Optional resource description.

Output Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidNo—Echoed connection UUID.
project_idstringNo—Resolved GCP project.
namestringNo—Compute sslCertificate name.
domainslistNo—Domains the managed cert covers.
descriptionstringNo—Resource description.
self_linkstringNo—Self link of the sslCertificate (bind this on the target HTTPS proxy).
operation_namestringNo—Compute operation name when created.
managed_statusstringNo—Managed cert status (e.g. PROVISIONING/ACTIVE) when known.
createdbooleanNo—True when created this run.
ssl_certificatejsonNo—Sanitized provider sslCertificate or operation.
failure_reasonstringNo—Human-readable failure reason.
failed_stepstringNo—Failed logical step.
failed_layerjsonNo—Engine failed layer if applicable.
failed_at_statestringNo—State where failure occurred.
errorstringNo—Error message.
error_typestringNo—Error class.

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—preflight—
creatingNoNo—complete—
preflightingNoNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingpreflightpreflighting—
preflightingexecutecreating—
creatingcompletecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "gcp.compute.ssl_certificate.ensure",
  "initial_data": {
    "connection_uuid": "value",
    "name": "value",
    "domains": "value"
  }
}