spad.site-creation-gcp ​
Provisions GCS + GCP CDN + DNS + HTTPS + origin restriction for a SPAD site
DAG-based site creation workflow for GCP-backed SPAD sites.
Provisions the full CDN-backed stack: GCS bucket, Cloud CDN edge, DNS A record, managed SSL cert, HTTPS proxy/forwarding rule, and origin restriction (CDN fill SA only).
Overview ​
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-spad |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
site_uuid | string | Yes | — | ID of the SPAD site to create |
organization_uuid | string | No | — | Organization ID |
slug | string | Yes | — | Site slug/identifier |
cloud_connection_uuid | string | Yes | — | GCP cloud connection ID |
dns_zone_ref | string | No | — | Cloud DNS managed zone name (e.g. example-zone) |
api_cloud_run_service | string | No | — | Optional Cloud Run service name to route /api to (e.g. 'calendar'). When set, SPAD becomes the single same-origin edge: static '/' from the bucket, /api to Cloud Run behind a serverless NEG. |
api_region | string | No | — | Region for the /api serverless NEG (e.g. 'us-central1'). Defaults to s3_region. |
api_path_prefix | string | No | /api | Path prefix routed to the Cloud Run backend (default '/api'). Matches '<prefix>' and '<prefix>/*'. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
site_uuid | string | Yes | — | Site marked active |
slug | string | No | — | Site slug propagated from input |
s3_bucket_name | string | No | — | GCS bucket name (stored in the cross-provider s3_bucket_name field) |
cloudfront_domain | string | No | — | HTTPS forwarding-rule IP (or HTTP IP fallback) used as the cross-provider edge identifier |
resources_created | list | No | — | Subset of gcs_bucket / gcp_cdn / gcp_dns_record / gcp_managed_cert / gcp_https_proxy / gcp_cdn_origin_restriction that were provisioned |
finalized_at | string | No | — | ISO8601 timestamp when the site was marked active |
create_api_neg | json | No | — | Terminal state data of the optional create_api_neg step (Cloud Run serverless NEG). Empty when api_cloud_run_service was not set. |
create_api_backend_service | json | No | — | Terminal state data of the optional create_api_backend_service step. Empty when api_cloud_run_service was not set. |
patch_url_map_api | json | No | — | Terminal state data of the optional patch_url_map_api step (re-upserts the SPAD url-map with the /api pathRule). Empty when api_cloud_run_service was not set. |
organization_uuid | string | No | — | Organization ID |
cloud_connection_uuid | string | No | — | GCP cloud connection ID |
dns_zone_ref | string | No | — | Cloud DNS managed zone name (e.g. example-zone) |
api_cloud_run_service | string | No | — | Optional Cloud Run service name to route /api to (e.g. 'calendar'). When set, SPAD becomes the single same-origin edge: static '/' from the bucket, /api to Cloud Run behind a serverless NEG. |
api_region | string | No | — | Region for the /api serverless NEG (e.g. 'us-central1'). Defaults to s3_region. |
api_path_prefix | string | No | — | Path prefix routed to the Cloud Run backend (default '/api'). Matches '<prefix>' and '<prefix>/*'. |
error | string | No | — | Engine-stamped failure metadata |
error_type | string | No | — | Engine-stamped failure metadata |
failed_at_state | json | No | — | Engine-stamped failure metadata |
failed_layer | json | No | — | Engine-stamped failure metadata |
failed_step | json | No | — | Engine-stamped failure metadata |
failure_reason | string | No | — | Engine-stamped failure metadata |
create_bucket | json | No | — | DAG step terminal state data |
configure_gcs_bucket | json | No | — | DAG step terminal state data |
create_cdn | json | No | — | DAG step terminal state data |
create_dns_record | json | No | — | DAG step terminal state data |
create_managed_cert | json | No | — | DAG step terminal state data |
create_https_proxy | json | No | — | DAG step terminal state data |
restrict_bucket_to_cdn | json | No | — | DAG step terminal state data |
finalize | json | No | — | DAG step terminal state data |
DAG Layers ​
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | create_bucket | spad.ltip.create_bucket | spad.compensation.noop |
| 2 | configure_gcs_bucket | spad.ltip.gcp.configure_bucket | spad.compensation.noop |
| 3 | create_cdn | spad.ltip.gcp.create_cdn | spad.compensation.noop |
| 4 | create_api_neg | gcp.compute.serverless_neg.create | spad.compensation.noop |
| 5 | create_api_backend_service | gcp.compute.backend_service.create | spad.compensation.noop |
| 6 | patch_url_map_api | gcp.compute.url_map.upsert | spad.compensation.noop |
| 7 | dns_and_cert | spad.ltip.gcp.create_dns_record, spad.ltip.gcp.create_managed_cert | spad.compensation.noop |
| 8 | create_https_proxy | spad.ltip.gcp.create_https_proxy | spad.compensation.noop |
| 9 | restrict_bucket_to_cdn | spad.ltip.gcp.restrict_bucket_to_cdn | spad.compensation.noop |
| 10 | finalize | spad.ltip.site-creation-finalize | — |
Execution Flow ​
Compensation ​
When any layer fails, its compensation steps run in reverse order to roll back the work completed so far.
Sub-workflows ​
| Sub-workflow | Step name |
|---|---|
spad.ltip.create_bucket | create_bucket |
spad.ltip.gcp.configure_bucket | configure_gcs_bucket |
spad.ltip.gcp.create_cdn | create_cdn |
gcp.compute.serverless_neg.create | create_api_neg |
gcp.compute.backend_service.create | create_api_backend_service |
gcp.compute.url_map.upsert | patch_url_map_api |
spad.ltip.gcp.create_dns_record | create_dns_record |
spad.ltip.gcp.create_managed_cert | create_managed_cert |
spad.ltip.gcp.create_https_proxy | create_https_proxy |
spad.ltip.gcp.restrict_bucket_to_cdn | restrict_bucket_to_cdn |
spad.ltip.site-creation-finalize | finalize |
spad.compensation.noop | ack_no_compensation_create_bucket |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "spad.site-creation-gcp",
"initial_data": {
"site_uuid": "value",
"slug": "value",
"cloud_connection_uuid": "value"
}
}