Skip to content
Proud to collaborate with Microsoft for Startups

gcp.secretmanager.secret.grant-access ​

Grant one or more principals access to read a Secret Manager secret.

Overview ​

PropertyValue
Workflow typeLinear
LibraryBase-gcp
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidYes—GCP CloudConnection UUID.
project_idstringNo—GCP project override.
secret_idstringYes—Secret Manager secret id.
memberslistYes—IAM members such as serviceAccount:name@example.iam.gserviceaccount.com.
rolestringNo—IAM role, default roles/secretmanager.secretAccessor.
conditionjsonNo—Optional IAM condition.
mergebooleanNo—Merge bindings instead of replacing.

Output Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidNo—Echoed connection UUID.
project_idstringNo—Effective project id.
secret_idstringNo—Secret id.
rolestringNo—IAM role applied.
memberslistNo—Members granted by the workflow.
conditionjsonNo—Optional IAM condition.
mergebooleanNo—Merge bindings instead of replacing.
etagstringNo—Resulting IAM policy etag.
changedbooleanNo—True when policy changed.
failure_reasonstringNo—Human-readable failure reason.
failed_stepstringNo—Failed logical step.
failed_layerjsonNo—Engine failed layer envelope.
failed_at_statestringNo—State where failure occurred.
errorstringNo—Error message.
error_typestringNo—Error class.

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—preflight—
grantingNoNo—complete—
preflightingNoNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingpreflightpreflighting—
preflightingexecutegranting—
grantingcompletecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "gcp.secretmanager.secret.grant-access",
  "initial_data": {
    "connection_uuid": "value",
    "secret_id": "value",
    "members": "value"
  }
}