Skip to content
Proud to collaborate with Microsoft for Startups

spad.ltip.gcp.restrict_bucket_to_cdn ​

Restrict GCS bucket IAM to Cloud CDN fill service account only

Remove allUsers objectViewer and grant Cloud CDN fill SA read on GCS bucket.

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-spad
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
s3_bucket_namestringYes—GCS bucket whose IAM should be restricted (named s3_bucket_name for cross-provider parity)
cloud_connection_uuidstringYes—GCP CloudConnection.id
slugstringNo—Site slug for context propagation
site_uuidstringNo—SpadSite.id for context propagation
organization_uuidstringNo—Organization that owns the site
workflow_run_idstringNo—Injected by the parent DAG; propagated through state_data
workflow_run_uuidstringNo—Parent workflow run ID stamped by the DAG engine (legacy alias)

Output Schema ​

FieldTypeRequiredDefaultDescription
gcp_cdn_origin_restrictedbooleanYes—True once allUsers viewer is removed and CDN fill SA binding is in place
gcp_cdn_fill_sastringYes—Cloud CDN fill service-account member granted objectViewer
gcp_project_numberstringYes—Numeric GCP project number used to derive the CDN fill SA
completed_atstringNo—ISO8601 timestamp when the step reached COMPLETED
failed_atstringNo—ISO8601 timestamp when the step reached FAILED
failure_reasonstringNo—Reason recorded on the failure path
workflow_run_idstringNo—Injected by the parent DAG; propagated through state_data
s3_bucket_namestringNo—GCS bucket whose IAM should be restricted (named s3_bucket_name for cross-provider parity)
cloud_connection_uuidstringNo—GCP CloudConnection.id
slugstringNo—Site slug for context propagation
site_uuidstringNo—SpadSite.id for context propagation
organization_uuidstringNo—Organization that owns the site
workflow_run_uuidstringNo—Parent workflow run ID stamped by the DAG engine (legacy alias)
errorstringNo—Engine-stamped failure metadata
error_typestringNo—Engine-stamped failure metadata
failed_at_statejsonNo—Engine-stamped failure metadata
failed_layerjsonNo—Engine-stamped failure metadata
failed_stepjsonNo—Engine-stamped failure metadata

States ​

StateInitialTerminalSuccessAuto-advanceDescription
initiatedYesNo—runStep accepted
runNoNo—completeRestricting bucket IAM
completedNoYesYes—Bucket restricted
failedNoYesNo—Bucket restriction failed

State Diagram ​

Transitions ​

FromActionToDescription
initiatedrunrunStart bucket IAM restriction
runcompletecompletedMark step completed
* (any state)failfailedMark step failed

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "spad.ltip.gcp.restrict_bucket_to_cdn",
  "initial_data": {
    "s3_bucket_name": "value",
    "cloud_connection_uuid": "value"
  }
}