Skip to content
Proud to collaborate with Microsoft for Startups

spad.site-creation-gcp ​

Provisions GCS + GCP CDN + DNS + HTTPS + origin restriction for a SPAD site

DAG-based site creation workflow for GCP-backed SPAD sites.

Provisions the full CDN-backed stack: GCS bucket, Cloud CDN edge, DNS A record, managed SSL cert, HTTPS proxy/forwarding rule, and origin restriction (CDN fill SA only).

Overview ​

PropertyValue
Workflow typeDag
LibraryApp-spad
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
site_uuidstringYes—ID of the SPAD site to create
organization_uuidstringNo—Organization ID
slugstringYes—Site slug/identifier
cloud_connection_uuidstringYes—GCP cloud connection ID
dns_zone_refstringNo—Cloud DNS managed zone name (e.g. example-zone)
api_cloud_run_servicestringNo—Optional Cloud Run service name to route /api to (e.g. 'calendar'). When set, SPAD becomes the single same-origin edge: static '/' from the bucket, /api to Cloud Run behind a serverless NEG.
api_regionstringNo—Region for the /api serverless NEG (e.g. 'us-central1'). Defaults to s3_region.
api_path_prefixstringNo/apiPath prefix routed to the Cloud Run backend (default '/api'). Matches '<prefix>' and '<prefix>/*'.

Output Schema ​

FieldTypeRequiredDefaultDescription
site_uuidstringYes—Site marked active
slugstringNo—Site slug propagated from input
s3_bucket_namestringNo—GCS bucket name (stored in the cross-provider s3_bucket_name field)
cloudfront_domainstringNo—HTTPS forwarding-rule IP (or HTTP IP fallback) used as the cross-provider edge identifier
resources_createdlistNo—Subset of gcs_bucket / gcp_cdn / gcp_dns_record / gcp_managed_cert / gcp_https_proxy / gcp_cdn_origin_restriction that were provisioned
finalized_atstringNo—ISO8601 timestamp when the site was marked active
create_api_negjsonNo—Terminal state data of the optional create_api_neg step (Cloud Run serverless NEG). Empty when api_cloud_run_service was not set.
create_api_backend_servicejsonNo—Terminal state data of the optional create_api_backend_service step. Empty when api_cloud_run_service was not set.
patch_url_map_apijsonNo—Terminal state data of the optional patch_url_map_api step (re-upserts the SPAD url-map with the /api pathRule). Empty when api_cloud_run_service was not set.
organization_uuidstringNo—Organization ID
cloud_connection_uuidstringNo—GCP cloud connection ID
dns_zone_refstringNo—Cloud DNS managed zone name (e.g. example-zone)
api_cloud_run_servicestringNo—Optional Cloud Run service name to route /api to (e.g. 'calendar'). When set, SPAD becomes the single same-origin edge: static '/' from the bucket, /api to Cloud Run behind a serverless NEG.
api_regionstringNo—Region for the /api serverless NEG (e.g. 'us-central1'). Defaults to s3_region.
api_path_prefixstringNo—Path prefix routed to the Cloud Run backend (default '/api'). Matches '<prefix>' and '<prefix>/*'.
errorstringNo—Engine-stamped failure metadata
error_typestringNo—Engine-stamped failure metadata
failed_at_statejsonNo—Engine-stamped failure metadata
failed_layerjsonNo—Engine-stamped failure metadata
failed_stepjsonNo—Engine-stamped failure metadata
failure_reasonstringNo—Engine-stamped failure metadata
create_bucketjsonNo—DAG step terminal state data
configure_gcs_bucketjsonNo—DAG step terminal state data
create_cdnjsonNo—DAG step terminal state data
create_dns_recordjsonNo—DAG step terminal state data
create_managed_certjsonNo—DAG step terminal state data
create_https_proxyjsonNo—DAG step terminal state data
restrict_bucket_to_cdnjsonNo—DAG step terminal state data
finalizejsonNo—DAG step terminal state data

DAG Layers ​

#LayerStepsCompensation
1create_bucketspad.ltip.create_bucketspad.compensation.noop
2configure_gcs_bucketspad.ltip.gcp.configure_bucketspad.compensation.noop
3create_cdnspad.ltip.gcp.create_cdnspad.compensation.noop
4create_api_neggcp.compute.serverless_neg.createspad.compensation.noop
5create_api_backend_servicegcp.compute.backend_service.createspad.compensation.noop
6patch_url_map_apigcp.compute.url_map.upsertspad.compensation.noop
7dns_and_certspad.ltip.gcp.create_dns_record, spad.ltip.gcp.create_managed_certspad.compensation.noop
8create_https_proxyspad.ltip.gcp.create_https_proxyspad.compensation.noop
9restrict_bucket_to_cdnspad.ltip.gcp.restrict_bucket_to_cdnspad.compensation.noop
10finalizespad.ltip.site-creation-finalize—

Execution Flow ​

Compensation ​

When any layer fails, its compensation steps run in reverse order to roll back the work completed so far.

Sub-workflows ​

Sub-workflowStep name
spad.ltip.create_bucketcreate_bucket
spad.ltip.gcp.configure_bucketconfigure_gcs_bucket
spad.ltip.gcp.create_cdncreate_cdn
gcp.compute.serverless_neg.createcreate_api_neg
gcp.compute.backend_service.createcreate_api_backend_service
gcp.compute.url_map.upsertpatch_url_map_api
spad.ltip.gcp.create_dns_recordcreate_dns_record
spad.ltip.gcp.create_managed_certcreate_managed_cert
spad.ltip.gcp.create_https_proxycreate_https_proxy
spad.ltip.gcp.restrict_bucket_to_cdnrestrict_bucket_to_cdn
spad.ltip.site-creation-finalizefinalize
spad.compensation.noopack_no_compensation_create_bucket

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "spad.site-creation-gcp",
  "initial_data": {
    "site_uuid": "value",
    "slug": "value",
    "cloud_connection_uuid": "value"
  }
}