spad.ltip.gcp.restrict_bucket_to_cdn ​
Restrict GCS bucket IAM to Cloud CDN fill service account only
Remove allUsers objectViewer and grant Cloud CDN fill SA read on GCS bucket.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Linear |
| Library | App-spad |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
s3_bucket_name | string | Yes | — | GCS bucket whose IAM should be restricted (named s3_bucket_name for cross-provider parity) |
cloud_connection_uuid | string | Yes | — | GCP CloudConnection.id |
slug | string | No | — | Site slug for context propagation |
site_uuid | string | No | — | SpadSite.id for context propagation |
organization_uuid | string | No | — | Organization that owns the site |
workflow_run_id | string | No | — | Injected by the parent DAG; propagated through state_data |
workflow_run_uuid | string | No | — | Parent workflow run ID stamped by the DAG engine (legacy alias) |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
gcp_cdn_origin_restricted | boolean | Yes | — | True once allUsers viewer is removed and CDN fill SA binding is in place |
gcp_cdn_fill_sa | string | Yes | — | Cloud CDN fill service-account member granted objectViewer |
gcp_project_number | string | Yes | — | Numeric GCP project number used to derive the CDN fill SA |
completed_at | string | No | — | ISO8601 timestamp when the step reached COMPLETED |
failed_at | string | No | — | ISO8601 timestamp when the step reached FAILED |
failure_reason | string | No | — | Reason recorded on the failure path |
workflow_run_id | string | No | — | Injected by the parent DAG; propagated through state_data |
s3_bucket_name | string | No | — | GCS bucket whose IAM should be restricted (named s3_bucket_name for cross-provider parity) |
cloud_connection_uuid | string | No | — | GCP CloudConnection.id |
slug | string | No | — | Site slug for context propagation |
site_uuid | string | No | — | SpadSite.id for context propagation |
organization_uuid | string | No | — | Organization that owns the site |
workflow_run_uuid | string | No | — | Parent workflow run ID stamped by the DAG engine (legacy alias) |
error | string | No | — | Engine-stamped failure metadata |
error_type | string | No | — | Engine-stamped failure metadata |
failed_at_state | json | No | — | Engine-stamped failure metadata |
failed_layer | json | No | — | Engine-stamped failure metadata |
failed_step | json | No | — | Engine-stamped failure metadata |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
initiated | Yes | No | — | run | Step accepted |
run | No | No | — | complete | Restricting bucket IAM |
completed | No | Yes | Yes | — | Bucket restricted |
failed | No | Yes | No | — | Bucket restriction failed |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
initiated | run | run | Start bucket IAM restriction |
run | complete | completed | Mark step completed |
* (any state) | fail | failed | Mark step failed |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "spad.ltip.gcp.restrict_bucket_to_cdn",
"initial_data": {
"s3_bucket_name": "value",
"cloud_connection_uuid": "value"
}
}