Meta tags:
Headings (most frequently used words):
node, js, python, java, the, with, code, cloud, up, identity, platform, to, pricing, run, tutorial, and, set, integrate, side, server, delete, resources, subject, tier, end, user, authentication, for, stay, organized, collections, save, categorize, content, based, on, your, preferences, objectives, costs, before, you, begin, gcloud, cli, defaults, retrieve, sample, visualize, architecture, understand, core, deploy, service, finishing, touches, try, it, out, clean, what, next, required, roles, locations, client, connect, sql, handle, sensitive, configuration, secret, manager, project, products, support, engage,
Text of the page (most frequently used words):
the (272), cloud (142), and (90), run (78), project (65), you (65), service (60), with (56), google (49), sql (45), your (45), for (44), from (44), #identity (41), that (39), create (39), user (38), services (35), secret (35), using (34), roles (33), delete (29), deploy (29), token (27), overview (27), this (26), platform (23), region (23), server (23), tutorial (22), use (22), code (21), gcloud (21), build (21), instance (20), console (20), firebase (20), resources (19), sample (19), project_id (18), can (18), configure (18), database (18), java (17), manager (17), account (17), iam (17), client (17), samples (16), container (16), idp (16), admin (16), name (15), select (15), environment (15), python (15), low (15), sign (14), config (14), access (14), secrets (14), worker (14), com (13), configuration (13), click (13), end (13), credentials (13), repository (13), error (13), return (13), const (13), storage (13), europe (13), functions (13), other (12), vote (12), new (12), auth (12), node (12), spring (12), application (12), get (12), jobs (12), pools (12), page (11), add (11), function (11), gpu (11), vpc (11), need (10), users (10), created (10), url (10), role (10), string (10), returns (10), authorization (10), uid (10), view (10), asia (10), manage (9), following (9), then (9), data (9), provider (9), connection (9), docker (9), request (9), postgres (9), sdk (9), header (9), volumes (9), execute (9), about (8), all (8), requests (8), has (8), projects (8), when (8), authentication (8), try (8), https (8), note (8), cloudsql (8), cloud_sql_credentials_secret (8), cli (8), uses (8), grant (8), json (8), db_user (8), db_name (8), cloud_sql_connection_name (8), postgresql (8), window (8), enable (8), err (8), development (8), git (8), best (8), practices (8), trigger (8), triggers (8), thumb (7), more (7), artifact (7), registry (7), also (7), dialog (7), limits (7), custom (7), through (7), format (7), signed (7), instances (7), password (7), memory (7), set (7), required (7), jdbctemplate (7), pool (7), connect (7), headers (7), pub (7), sub (7), maximum (7), products (6), are (6), authenticate (6), learn (6), next (6), image (6), browser (6), provided (6), apis (6), variables (6), which (6), tools (6), file (6), db_password (6), not (6), app (6), parse (6), logger (6), catch (6), object (6), retrieve (6), engine (6), creds (6), credconfig (6), authheader (6), verify (6), response (6), alert (6), log (6), docs (6), how (6), security (6), migrate (6), agents (6), metrics (6), github (5), pricing (5), down (5), information (5), under (5), send (5), deployed (5), plan (5), might (5), used (5), existing (5), management (5), sensitive (5), complete (5), after (5), method (5), allow (5), jib (5), containers (5), datasource (5), values (5), web (5), throw (5), secure (5), local (5), extract (5), integrate (5), logging (5), selecting (5), cost (5), usage (5), resourcemanager (5), permission (5), based (5), networking (5), migration (5), gpus (5), network (5), traffic (5), source (5), job (5), eventarc (5), invoke (5), português (4), español (4), status (4), understand (4), content (4), its (4), developers (4), gserviceaccount (4), added (4), setup (4), costs (4), billing (4), deployment (4), copy (4), oauth (4), logs (4), providers (4), version (4), pkg (4), dev (4), credential (4), builds (4), location (4), policy (4), associated (4), gcp (4), cpu (4), infrastructure (4), static (4), make (4), sure (4), def (4), databases (4), private (4), unix (4), sqlalchemy (4), host (4), else (4), decodedtoken (4), properly (4), expired (4), req (4), www (4), their (4), script (4), clone (4), west1 (4), south1 (4), editor (4), selector (4), write (4), checks (4), inference (4), direct (4), scaling (4), health (4), optimize (4), dependencies (4), events (3), started (3), system (3), support (3), contact (3), see (3), otherwise (3), explore (3), tutorials (3), methods (3), into (3), default (3), replace (3), don (3), type (3), want (3), multiple (3), have (3), such (3), instead (3), tasks (3), document (3), any (3), keep (3), these (3), will (3), should (3), button (3), step (3), enter (3), domain (3), authorize (3), variable (3), cloud_sql_instance_name (3), process (3), push (3), images (3), must (3), password_secret (3), username (3), steps (3), supply (3), external (3), unable (3), formatted (3), hashmap (3), null (3), public (3), str (3), been (3), env (3), provides (3), db_config (3), db_socket_dir (3), db_pass (3), args (3), base (3), int (3), decoded (3), correct (3), split (3), func (3), res (3), require (3), side (3), text (3), await (3), team (3), adds (3), result (3), javascript (3), back (3), reference (3), shows (3), contains (3), alternatively (3), zip (3), download (3), googlecloudplatform (3), east1 (3), northamerica (3), specific (3), managed (3), permissions (3), test (3), serviceusage (3), free (3), guides (3), hosting (3), frameworks (3), monitoring (3), solutions (3), distributed (3), introduction (3), mcp (3), connectors (3), optimization (3), autoscale (3), labels (3), ephemeral (3), disk (3), cifs (3), smb (3), nfs (3), volume (3), mounts (3), entrypoint (3), retries (3), firestore (3), concurrent (3), product (3), 한국어 (2), 日本語 (2), עברית (2), brasil (2), italiano (2), indonesia (2), français (2), américa (2), latina (2), deutsch (2), english (2), our (2), terms (2), site (2), youtube (2), architecture (2), last (2), updated (2), 2026 (2), utc (2), except (2), licensed (2), details (2), license (2), feedback (2), connecting (2), unset (2), remove (2), during (2), they (2), list (2), deleting (2), avoid (2), work (2), without (2), additional (2), choose (2), flow (2), previous (2), out (2), firebaseapp (2), save (2), icon (2), edit (2), authorized (2), redirect (2), domains (2), requires (2), finishing (2), touches (2), latest (2), update (2), unauthenticated (2), load (2), begin (2), verifies (2), submit (2), tag (2), binding (2), member (2), serviceaccount (2), secretmanager (2), accounts (2), automatic (2), follow (2), described (2), initialize (2), authdomain (2), apikey (2), client_secret (2), client_id (2), email (2), one (2), api (2), manual (2), loads (2), dictionary (2), dict (2), get_cred_config (2), tostring (2), resource (2), runtime (2), handle (2), jdbc (2), bean (2), allows (2), none (2), pgsql (2), 5432 (2), unix_sock (2), pg8000 (2), socket (2), dbsocketpath (2), knex (2), async (2), httpstatus (2), responsestatusexception (2), idtoken (2), verifyidtoken (2), authenticatejwt (2), decorated_function (2), kwargs (2), decoded_token (2), 401 (2), 403 (2), exception (2), extracts (2), callable (2), sendstatus (2), fetch (2), currentuser (2), reporting (2), displayname (2), them (2), gstatic (2), firebasejs (2), src (2), first (2), core (2), sdks (2), authenticated (2), sends (2), own (2), control (2), redirected (2), votes (2), nodejs (2), already (2), west4 (2), west3 (2), west2 (2), southamerica (2), northeast2 (2), northeast1 (2), central2 (2), central1 (2), australia (2), southeast2 (2), southeast1 (2), india (2), south (2), subject (2), tier (2), available (2), regions (2), latency (2), but (2), across (2), locations (2), within (2), supported (2), defaults (2), basic (2), administrator (2), owner (2), enabled (2), procedure (2), finish (2), removing (2), creator (2), projectcreator (2), doesn (2), granted (2), perform (2), world (2), components (2), least (2), privilege (2), protect (2), processes (2), does (2), documentation (2), languages (2), observability (2), industry (2), hybrid (2), multicloud (2), analytics (2), pipelines (2), compute (2), troubleshoot (2), oci (2), assisted (2), llm (2), execution (2), remote (2), adk (2), a2a (2), prometheus (2), controls (2), shared (2), connector (2), automate (2), workflows (2), description (2), metadata (2), systems (2), capacity (2), rollbacks (2), revisions (2), continuous (2), tags (2), timeout (2), testing (2), workflow (2), runtimes (2), configurations (2), http (2), serving (2), serve (2), results (2), php (2), ruby (2), prepare (2), develop (2), cases (2), cross (2), technology (2), areas (2), close (2), subscribe, newsletter, third, decade, climate, action, join, cookies, privacy, tech, twitter, blog, engage, training, certification, center, getting, release, notes, community, forums, sales, marketplace, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, incorrectinformationorsamplecode, missing, missingtheinformationsamplesineed, otherdown, tell, noted, registered, trademark, oracle, affiliates, policies, apache, creative, commons, attribution, demos, review, ways, managing, dive, deeper, what, command, incur, until, receive, shut, effects, architectures, quickstarts, reusing, help, exceeding, quota, future, preserve, urls, selected, inside, whole, appspot, ids, lost, done, everything, deleted, caution, easiest, way, eliminate, changes, charges, clean, continue, developing, remember, restricted, rest, given, many, authenticates, securely, manages, success, look, like, navigate, handler, field, paste, bottom, pencil, beside, uri, uris, describe, value, locate, find, anytime, right, panel, clicking, pen, allowed, resolved, startup, time, recommends, pin, particular, rather, than, flags, specify, respectively, manually, authenticating, mvn, compile, dimage, maven, plugin, helper, common, optimizes, dockerfile, having, installed, building, each, names, unique, artifacts, repositories, secretaccessor, replication, versioned, postgres_16, 7680mb, root, cloud_sql_region, provisioning, yet, still, settings, top, obtain, agree, audience, displayed, emails, runtimeexception, jsonsyntaxexception, class, fromjson, gson, illegalstateexception, getenv, getconfig, environ, stored, utf8, secret_id, versions, passed, centralized, injects, integration, interact, libraries, mysql, auto, coupled, operations, querying, modifying, votecontroller, final, vars, uncomment, starter, initialized, info, description_encoding, dialect, query, drivername, socket_path, equivalent, create_engine, initializes, init_unix_connection_engine, establish, db_socket_path, connectwithunixsockets, param, sockets, connects, unauthorized, forbidden, firebaseauthexception, getuid, getinstance, firebaseauth, firebasetoken, map, verify_id_token, firebase_admin, wraps, jwt_authenticated, initializeapp, sent, something, went, wrong, please, again, submitting, reload, body, bearer, form, urlencoded, post, getidtoken, refresh, current, jwt, identify, successfully, signs, mint, capture, route, implementation, example, refer, stackdriver, library, failed, retry, check, message, welcome, logged, along, signinwithpopup, googleapis, userinfo, addscope, googleauthprovider, signin, handles, prompting, redirects, listed, always, api_key, order, holds, imports, necessary, implemented, receives, confirming, appropriately, fetches, login, welcomes, makes, diagram, being, visualize, change, directory, machine, dashboard, las, vegas, salt, lake, city, los, angeles, santiago, chile, sao, paulo, brazil, toronto, montreal, dammam, doha, zurich, switzerland, west6, frankfurt, germany, london, turin, west12, berlin, west10, warsaw, poland, melbourne, sydney, delhi, south2, jakarta, singapore, seoul, korea, northeast3, hong, kong, east2, johannesburg, africa, oregon, dallas, columbus, east5, northern, virginia, east4, carolina, iowa, mexico, tel, aviv, paris, west9, milan, west8, netherlands, belgium, madrid, southwest1, stockholm, north2, finland, north1, bangkok, southeast3, mumbai, osaka, tokyo, taiwan, meeting, availability, durability, requirements, primary, factors, where, generally, nearest, consider, together, affect, well, regional, means, runs, located, redundantly, zones, choice, chosen, contain, shouldn, production, able, predefined, granting, folders, organizations, serviceusageconsumer, consumer, serviceaccountuser, projectiamadmin, oauthconfig, identityplatform, serviceaccountcreator, cloudbuild, artifactregistry, repoadmin, ask, likely, serviceusageadmin, evaluate, real, scenarios, customers, 300, credits, workloads, before, generate, estimate, projected, eligible, trial, calculator, billable, minimal, backend, objectives, minimizes, risks, tool, term, refers, federated, workforce, federation, simplicity, acquire, however, stores, providing, valid, favorite, domestic, animal, voting, consisting, categorize, preferences, stay, organized, collections, home, known, issues, troubleshooting, errors, gke, kubernetes, vmware, tanzu, music, compliant, strategy, foundry, heroku, aws, lambda, 1st, gen, cookbook, vibe, coding, accelerated, video, transcoding, ffmpeg, batch, fine, tune, llms, hugging, face, transformers, opencv, acceleration, gemma, models, ollama, automation, servers, n8n, tracing, audit, opentelemetry, built, monitor, multi, tenant, platforms, running, untrusted, software, chain, insights, constraints, customer, encryption, keys, threat, detection, binary, armor, iap, audiences, design, mesh, restrict, endpoint, ingress, outbound, address, standard, dual, stack, ipv4, ipv6, register, ips, dns, pull, subscriptions, runners, kafka, autoscaler, scale, count, splits, background, checkpoints, stop, executions, task, parallelism, scheduled, completion, event, driven, zonal, redundancy, general, tips, grpc, routed, entries, processing, call, subscription, asynchronous, series, part, schedule, asynchronously, websocket, chat, stream, websockets, webhook, target, updates, language, minimum, autoscaling, sandboxes, port, recommender, per, performance, gradual, rollouts, frontend, proxying, nginx, session, affinity, failover, assets, cdn, mapping, compose, sources, codelabs, spanner, bigquery, net, compare, commands, install, package, containerize, shell, sveltekit, nuxt, angular, ssr, kotlin, agent, kit, streamlit, smolagents, langchain, gradio, fastapi, flask, hello, good, fit, contract, model, discover, start, skip, main,
Text of the page (random words):
e permissions that you need to complete the tutorial ask your administrator to grant you the following iam roles on your project artifact registry repository administrator roles artifactregistry repoadmin cloud build editor roles cloudbuild builds editor cloud run admin roles run admin cloud sql admin roles cloudsql admin create service accounts roles iam serviceaccountcreator identity platform admin roles identityplatform admin oauth config editor roles oauthconfig editor project iam admin roles resourcemanager projectiamadmin secret manager admin roles secretmanager admin service account user roles iam serviceaccountuser service usage consumer roles serviceusage serviceusageconsumer storage admin roles storage admin for more information about granting roles see manage access to projects folders and organizations you might also be able to get the required permissions through custom roles or other predefined roles note iam basic roles might also contain permissions to complete the tutorial you shouldn t grant basic roles in a production environment but you can grant them in a development or test environment set up gcloud cli defaults to configure google cloud cli with defaults for your cloud run service set your default project gcloud config set project project_id replace project_id with the name of the project you created for this tutorial configure google cloud cli for your chosen region gcloud config set run region region replace region with the supported cloud run region of your choice cloud run locations cloud run is regional which means the infrastructure that runs your cloud run services is located in a specific region and is managed by google to be redundantly available across all the zones within that region meeting your latency availability or durability requirements are primary factors for selecting the region where your cloud run services are run you can generally select the region nearest to your users but you should consider the location of the other google cloud products that are used by your cloud run service using google cloud products together across multiple locations can affect your service s latency as well as cost cloud run is available in the following regions subject to tier 1 pricing asia east1 taiwan asia northeast1 tokyo asia northeast2 osaka asia south1 mumbai india asia southeast3 bangkok europe north1 finland low co 2 europe north2 stockholm low co 2 europe southwest1 madrid low co 2 europe west1 belgium low co 2 europe west4 netherlands low co 2 europe west8 milan europe west9 paris low co 2 me west1 tel aviv northamerica south1 mexico us central1 iowa low co 2 us east1 south carolina us east4 northern virginia us east5 columbus us south1 dallas low co 2 us west1 oregon low co 2 subject to tier 2 pricing africa south1 johannesburg asia east2 hong kong asia northeast3 seoul south korea asia southeast1 singapore asia southeast2 jakarta asia south2 delhi india australia southeast1 sydney australia southeast2 melbourne europe central2 warsaw poland europe west10 berlin europe west12 turin europe west2 london uk low co 2 europe west3 frankfurt germany europe west6 zurich switzerland low co 2 me central1 doha me central2 dammam northamerica northeast1 montreal low co 2 northamerica northeast2 toronto low co 2 southamerica east1 sao paulo brazil low co 2 southamerica west1 santiago chile low co 2 us west2 los angeles us west3 salt lake city us west4 las vegas if you already created a cloud run service you can view the region in the cloud run dashboard in the google cloud console ok retrieve the code sample to retrieve the code sample for use clone the sample app repository to your local machine node js git clone https github com googlecloudplatform nodejs docs samples git alternatively you can download the sample as a zip file and extract it python git clone https github com googlecloudplatform python docs samples git alternatively you can download the sample as a zip file and extract it java git clone https github com googlecloudplatform java docs samples git alternatively you can download the sample as a zip file and extract it change to the directory that contains the cloud run sample code node js cd nodejs docs samples run idp sql python cd python docs samples run idp sql java cd java docs samples run idp sql visualize the architecture diagram shows an end user logging in through a google sign in dialog provided by identity platform and then being redirected back to cloud run with the user s identity an end user makes the first request to the cloud run server the client loads in the browser the user provides login credentials through the google sign in dialog from identity platform an alert welcomes the signed in user control is redirected back to the server the end user votes using the client which fetches an id token from identity platform and adds it to the vote request header when the server receives the request it verifies the identity platform id token confirming that the end user is appropriately authenticated then server sends the vote to cloud sql using its own credentials understand the core code the sample is implemented as client and server as described next integrate with identity platform client side code this sample uses firebase sdks to integrate with identity platform in order to sign in and manage users to connect to identity platform the client side javascript holds the reference to the project s credentials as a config object and imports the necessary firebase javascript sdks const config apikey api_key authdomain project_id firebaseapp com firebase app the core firebase sdk is always required and must be listed first script src https www gstatic com firebasejs 7 18 firebase app js script add firebase auth service script src https www gstatic com firebasejs 7 18 firebase auth js script the firebase javascript sdk handles the sign in flow by prompting the end user to sign in to their google account using a dialog window it then redirects them back to the service function signin const provider new firebase auth googleauthprovider provider addscope https www googleapis com auth userinfo email firebase auth signinwithpopup provider then result returns the signed in user along with the provider s credential console log result user displayname logged in window alert welcome result user displayname catch err console log error during sign in err message window alert sign in failed retry or check your browser logs note to capture browser logging you might want to route logs to cloud logging for an implementation example refer to stackdriver error reporting library when a user successfully signs in the client uses firebase methods to mint an id token the client adds the id token to the authorization header of its request to the server async function vote team if firebase auth currentuser retrieve jwt to identify the user to the identity platform service returns the current token if it has not expired otherwise this will refresh the token and return a new one try const token await firebase auth currentuser getidtoken const response await fetch method post headers content type application x www form urlencoded authorization bearer token body team team send application data vote if response ok const text await response text window alert text window location reload catch err console log error when submitting vote err window alert something went wrong please try again else window alert user not signed in integrate with identity platform server side code the server uses the firebase admin sdk to verify the user id token sent from the client if the provided id token has the correct format is not expired and is properly signed the method returns the decoded id token the server extracts the identity platform uid for that user node js const firebase require firebase admin initialize firebase admin sdk firebase initializeapp extract and verify id token from header const authenticatejwt req res next const authheader req headers authorization if authheader const token authheader split 1 if the provided id token has the correct format is not expired and is properly signed the method returns the decoded id token firebase auth verifyidtoken token then decodedtoken const uid decodedtoken uid req uid uid next catch err req logger error error with authentication err return res sendstatus 403 else return res sendstatus 401 python def jwt_authenticated func callable int callable int use the firebase admin sdk to parse authorization header to verify the user id token the server extracts the identity platform uid for that user wraps func def decorated_function args a kwargs a a header request headers get authorization none if header token header split 1 try decoded_token firebase_admin auth verify_id_token token except exception as e logger exception e return response status 403 response f error with authentication e else return response status 401 request uid decoded_token uid return func args kwargs return decorated_function java extract and verify id token from header private string authenticatejwt map string string headers string authheader headers get authorization null headers get authorization headers get authorization if authheader null string idtoken authheader split 1 if the provided id token has the correct format is not expired and is properly signed the method returns the decoded id token try firebasetoken decodedtoken firebaseauth getinstance verifyidtoken idtoken string uid decodedtoken getuid return uid catch firebaseauthexception e logger error error with authentication e tostring throw new responsestatusexception httpstatus forbidden e else logger error error no authorization header throw new responsestatusexception httpstatus unauthorized connect the server to cloud sql the server connects to the cloud sql instance unix domain socket using the format cloudsql cloud_sql_connection_name node js connect to the cloud sql instance through unix sockets param object credconfig the cloud sql connection configuration from secret manager returns object knex s postgresql client const connectwithunixsockets async credconfig const dbsocketpath process env db_socket_path cloudsql establish a connection to the database return knex client pg connection user credconfig db_user e g my user password credconfig db_password e g my user password database credconfig db_name e g my database host dbsocketpath credconfig cloud_sql_connection_name config python def init_unix_connection_engine db_config dict str int sqlalchemy engine base engine initializes a unix socket connection pool for a cloud sql instance of postgresql args db_config a dictionary with connection pool config returns a sqlalchemy engine instance creds credentials get_cred_config db_user creds db_user db_pass creds db_password db_name creds db_name db_socket_dir creds get db_socket_dir cloudsql cloud_sql_connection_name creds cloud_sql_connection_name pool sqlalchemy create_engine equivalent url postgres pg8000 db_user db_pass db_name unix_sock socket_path cloud_sql_instance_name s pgsql 5432 sqlalchemy engine url url create drivername postgresql pg8000 username db_user e g my database user password db_pass e g my database password database db_name e g my database name query unix_sock f db_socket_dir cloud_sql_connection_name s pgsql 5432 e g cloudsql project name instance region instance name db_config pool dialect description_encoding none logger info database engine initialized from unix connection return pool java use the spring cloud google cloud postgresql starter integration to interact with your postgresql databases in cloud sql using spring jdbc libraries set your cloud sql for mysql config to auto configure a datasource bean which coupled with spring jdbc provides a jdbctemplate object bean that allows for operations such as querying and modifying a database uncomment and add env vars for local development spring datasource username db_user spring datasource password db_password spring cloud gcp sql database name db_name spring cloud gcp sql instance connection name cloud_sql_connection_name private final jdbctemplate jdbctemplate public votecontroller jdbctemplate jdbctemplate this jdbctemplate jdbctemplate handle sensitive configuration with secret manager secret manager provides centralized and secure storage of sensitive data such as cloud sql configuration the server injects the cloud sql credentials from secret manager at runtime using an environment variable learn more about using secrets with cloud run node js cloud_sql_credentials_secret is the resource id of the secret passed in by environment variable format projects project_id secrets secret_id versions version const cloud_sql_credentials_secret process env if cloud_sql_credentials_secret try parse the secret that has been added as a json string to retrieve database credentials return json parse cloud_sql_credentials_secret tostring utf8 catch err throw error unable to parse secret from secret manager make sure that the secret is json formatted err python def get_cred_config dict str str retrieve cloud sql credentials stored in secret manager or default to environment variables returns a dictionary with cloud sql credential values secret os environ get cloud_sql_credentials_secret if secret return json loads secret java retrieve config from secret manager public static hashmap string object getconfig string secret system getenv cloud_sql_credentials_secret if secret null throw new illegalstateexception cloud_sql_credentials_secret is required try hashmap string object config new gson fromjson secret hashmap class return config catch jsonsyntaxexception e logger error unable to parse secret from secret manager make sure that it is json formatted e throw new runtimeexception unable to parse secret from secret manager make sure that it is json formatted set up identity platform identity platform requires manual setup in the google cloud console in the google cloud console enable the identity platform api enable the api configure your project in a new window go to the google auth platform overview page go to overview click get started and follow the project configuration setup in the app information dialog supply the application name select one of the displayed user support emails in the audience dialog select external in the contact information dialog enter a contact email agree to the user data policy then click create create and obtain your oauth client id and secret in the google cloud console go to the apis services credentials page go to credentials at the top of the page click create credentials and select oauth client id from application type select web application and supply the name click create the client_id and client_secret values will be used in the next step configure google as a provider in the google cloud console go to the identity providers page go to identity providers click add a provider select google from the list in the web sdk configuration se...
|