Skip to main content

GCP Provider

Manage Google Cloud Platform resources declaratively through the Pragmatiks platform. This provider uses user-provided service account credentials (multi-tenant SaaS pattern) to create and manage GCP infrastructure.

Supported Services

Service Resource Description
Secret Manager gcp/secret Store and version sensitive data
GKE gcp/gke Kubernetes clusters (Autopilot and Standard)
Cloud SQL gcp/cloudsql/database_instance Managed database instances (PostgreSQL, MySQL, SQL Server)
Cloud SQL gcp/cloudsql/database Databases within a Cloud SQL instance
Cloud SQL gcp/cloudsql/user Database users within a Cloud SQL instance

Prerequisites

  1. GCP Project with billing enabled.
  2. Service account with appropriate IAM roles per resource:
    • Secret Manager: roles/secretmanager.admin
    • GKE: roles/container.admin
    • Cloud SQL: roles/cloudsql.admin
  3. GCP APIs enabled on the project:
    • secretmanager.googleapis.com
    • container.googleapis.com
    • sqladmin.googleapis.com
    • logging.googleapis.com (for health checks and log streaming)
  4. Service account key exported as JSON (passed via credentials field on each resource).

Installation

pragma providers install gcp

Resources

Secret (gcp/secret)

Manages secrets in GCP Secret Manager. Creates versioned secrets with automatic replication.

Config fields:

Field Type Required Mutable Description
project_id string yes no GCP project ID
secret_id string yes no Secret identifier (unique per project)
data string yes yes Secret payload to store
credentials object/string yes yes GCP service account credentials JSON

Outputs: resource_name, version_name, version_id (version_name and version_id are null when the secret has no enabled version)

Example:

resources:
  - name: api-key
    provider: gcp
    type: secret
    config:
      project_id: my-gcp-project
      secret_id: api-key
      data: "sk-my-secret-value"
      credentials:
        $ref: gcp-credentials

Behavior:

  • Create: Creates the secret and an initial version. Idempotent -- if the secret already exists, adds a new version.
  • Observe: Reads the secret and its latest enabled version.
  • Update: Adds a new secret version when data differs from the latest enabled version. Previous versions are retained.
  • Delete: Deletes the secret and all its versions.

GKE Cluster (gcp/gke)

Manages GKE clusters in either Autopilot (default) or Standard mode. Includes health checks and log streaming from Cloud Logging.

Config fields:

Field Type Required Mutable Default Description
project_id string yes no -- GCP project ID
credentials object/string yes yes -- GCP service account credentials JSON
location string yes no -- Region or zone (e.g., europe-west4)
name string yes no -- Cluster name (lowercase, 1-40 chars)
autopilot bool no no true Use Autopilot mode
network string no no "default" VPC network name
subnetwork string no no -- VPC subnetwork name
release_channel string no yes "REGULAR" Release channel: RAPID, REGULAR, STABLE
initial_node_count int no no 1 Nodes in default pool (Standard only)
machine_type string no no "e2-medium" Node machine type (Standard only)
disk_size_gb int no no 100 Boot disk size in GB (Standard only)

Outputs: name, endpoint, cluster_ca_certificate, location, console_url, logs_url

Example (Autopilot):

resources:
  - name: prod-cluster
    provider: gcp
    type: gke
    config:
      project_id: my-gcp-project
      location: europe-west4
      name: prod-cluster
      autopilot: true
      release_channel: STABLE
      credentials:
        $ref: gcp-credentials

Example (Standard):

resources:
  - name: dev-cluster
    provider: gcp
    type: gke
    config:
      project_id: my-gcp-project
      location: europe-west4-a
      name: dev-cluster
      autopilot: false
      initial_node_count: 3
      machine_type: e2-standard-4
      disk_size_gb: 200
      credentials:
        $ref: gcp-credentials

Behavior:

  • Create: Creates the cluster and polls until it serves, in RUNNING or DEGRADED state (up to 19 minutes). Idempotent -- if the cluster already exists, waits for it to serve.
  • Observe: Reads the cluster by project, location and name.
  • Update: Waits for the cluster's pending operations; when the live channel differs, moves the cluster to the configured release_channel and waits for the update. Either way, waits for the cluster to serve, in RUNNING or DEGRADED state. credentials is mutable too; every other field is immutable and requires delete and recreate.
  • Delete: Deletes the cluster and polls until fully removed.
  • Health: Reports healthy (RUNNING), degraded (DEGRADED/PROVISIONING/RECONCILING), or unhealthy (ERROR/not found).
  • Logs: Streams cluster logs from Cloud Logging.

Cloud SQL Database Instance (gcp/cloudsql/database_instance)

Manages Cloud SQL instances for PostgreSQL, MySQL, and SQL Server. Supports configurable tiers, high availability, backups, and network access. Includes health checks and log streaming.

Config fields:

Field Type Required Mutable Default Description
project_id string yes no -- GCP project ID
credentials object/string yes yes -- GCP service account credentials JSON
region string yes no -- GCP region (e.g., europe-west4)
instance_name string yes no -- Instance name (unique per project, 1-98 chars)
database_version string no no "POSTGRES_15" Engine version (e.g., POSTGRES_15, MYSQL_8_0)
tier string no yes "db-f1-micro" Machine tier (e.g., db-custom-1-3840)
availability_type string no yes "ZONAL" ZONAL or REGIONAL (high availability)
backup_enabled bool no yes true Enable automatic backups
deletion_protection bool no yes false Prevent accidental deletion
authorized_networks list[string] no yes [] CIDR ranges allowed to connect
enable_public_ip bool no yes true Assign a public IP address

Outputs: connection_name, public_ip, private_ip, console_url, logs_url

Example:

resources:
  - name: prod-db-instance
    provider: gcp
    type: cloudsql/database_instance
    config:
      project_id: my-gcp-project
      region: europe-west4
      instance_name: prod-postgres
      database_version: POSTGRES_15
      tier: db-custom-2-7680
      availability_type: REGIONAL
      backup_enabled: true
      deletion_protection: true
      authorized_networks:
        - "10.0.0.0/8"
      credentials:
        $ref: gcp-credentials

Behavior:

  • Create: Creates the instance and polls until RUNNABLE (up to 19 minutes). Generates a random root password. Idempotent.
  • Observe: Reads the instance by project and instance name.
  • Update: Patches mutable settings (tier, availability, backups, network config), waits for the patch operation, then for RUNNABLE.
  • Delete: Deletes the instance. Respects deletion_protection -- disable it first to allow deletion.
  • Health: Reports healthy (RUNNABLE), degraded (PENDING_CREATE/MAINTENANCE), or unhealthy.
  • Logs: Streams instance logs from Cloud Logging.

Cloud SQL Database (gcp/cloudsql/database)

Creates a database within a Cloud SQL instance. Requires a dependency on a gcp/cloudsql/database_instance resource.

Config fields:

Field Type Required Mutable Description
instance Dependency yes no Reference to a cloudsql/database_instance resource
database_name string yes no Name of the database to create

Outputs: database_name, instance_name, host, port, url

Example:

resources:
  - name: prod-db-instance
    provider: gcp
    type: cloudsql/database_instance
    config:
      project_id: my-gcp-project
      region: europe-west4
      instance_name: prod-postgres
      credentials:
        $ref: gcp-credentials

  - name: app-database
    provider: gcp
    type: cloudsql/database
    config:
      instance:
        $ref: prod-db-instance
      database_name: myapp

Behavior:

  • Create: Creates the database in the target instance and waits for the operation. Idempotent.
  • Observe: Reads the database by database_name.
  • Update: Returns current database state. Every field is immutable.
  • Delete: Drops the database from the instance and waits for the operation.
  • Outputs include a connection URL in the format postgresql://host:port/database_name.

Cloud SQL User (gcp/cloudsql/user)

Creates a database user within a Cloud SQL instance. Requires a dependency on a gcp/cloudsql/database_instance resource.

Config fields:

Field Type Required Mutable Description
instance Dependency yes no Reference to a cloudsql/database_instance resource
username string yes no Database username
password string yes yes Database password

Outputs: username, instance_name, host

Example:

resources:
  - name: prod-db-instance
    provider: gcp
    type: cloudsql/database_instance
    config:
      project_id: my-gcp-project
      region: europe-west4
      instance_name: prod-postgres
      credentials:
        $ref: gcp-credentials

  - name: app-user
    provider: gcp
    type: cloudsql/user
    config:
      instance:
        $ref: prod-db-instance
      username: app_service
      password:
        $ref: db-password-secret

Behavior:

  • Create: Creates the user in the target instance and waits for the operation. Idempotent.
  • Observe: Reads the user by username.
  • Update: Password changes are applied in place and waited on.
  • Delete: Drops the user from the instance and waits for the operation.

Full Stack Example

A complete Cloud SQL setup with instance, database, user, and credentials stored in Secret Manager:

resources:
  - name: db-password
    provider: gcp
    type: secret
    config:
      project_id: my-gcp-project
      secret_id: db-password
      data: "my-secure-password"
      credentials:
        $ref: gcp-credentials

  - name: prod-instance
    provider: gcp
    type: cloudsql/database_instance
    config:
      project_id: my-gcp-project
      region: europe-west4
      instance_name: prod-postgres
      database_version: POSTGRES_15
      tier: db-custom-2-7680
      availability_type: REGIONAL
      backup_enabled: true
      credentials:
        $ref: gcp-credentials

  - name: app-db
    provider: gcp
    type: cloudsql/database
    config:
      instance:
        $ref: prod-instance
      database_name: myapp

  - name: app-user
    provider: gcp
    type: cloudsql/user
    config:
      instance:
        $ref: prod-instance
      username: app_service
      password: "my-secure-password"

Credentials

All resources require a credentials field containing GCP service account credentials as either a JSON object or a JSON string. In production, use a $ref to a secret resource to inject credentials securely.

The provider uses explicit credentials (not Application Default Credentials) to support multi-tenant deployments where each user operates in their own GCP project.

Development

# Lint and type check
task gcp:check

# Format
task gcp:format

Metadata

Release files for pragmatiks-gcp-provider 7.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pragmatiks-gcp-provider 7.1.1
File Size Uploaded
pragmatiks_gcp_provider-7.1.1.tar.gz 21.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pragmatiks-gcp-provider 7.1.1
File Interpreter ABI Platform
pragmatiks_gcp_provider-7.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 50.6 kB

Release files / pragmatiks_gcp_provider-7.1.1.tar.gz

Download URL pragmatiks_gcp_provider-7.1.1.tar.gz
Size 21.5 kB
Tags Source
SHA-256 checksum
How to use checksums
b326ded9360ff91646f8d8fbb175f1b9b9e3f7951b65570991cae3abe46fa87e
BLAKE2b-256 checksum
How to use checksums
a2e5a41e386ca42002cae11dbefa823d123169e9188e0c7a01dacbd883f42b4d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pragmatiks_gcp_provider-7.1.1-py3-none-any.whl

Download URL pragmatiks_gcp_provider-7.1.1-py3-none-any.whl
Size 29.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ac631547992587147c4ae6bd39ba8991f7fb6d7dd615d1f2f3c680c5dd1902e6
BLAKE2b-256 checksum
How to use checksums
02276c2482f1ddfd0b800aa357d51ed770a8c6c4cd4c39dc6714f74b34c62475
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

7.2.0

2 release files

This release

7.1.1 This release

2 release files

7.1.0

2 release files

7.0.0

2 release files

6.0.9

2 release files

6.0.8

2 release files

6.0.7

2 release files

6.0.6

2 release files

6.0.5

2 release files

6.0.4

2 release files

6.0.3

2 release files

6.0.2

2 release files

6.0.1

2 release files

6.0.0

2 release files

5.0.2

2 release files

5.0.1

2 release files

5.0.0

2 release files

4.0.0

2 release files

3.0.0

2 release files

2.0.0

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.66.0

2 release files

0.65.0

2 release files

0.64.0

2 release files

0.63.0

2 release files

0.62.0

2 release files

0.61.0

2 release files

0.60.0

2 release files

0.59.0

2 release files

0.58.0

2 release files

0.57.0

2 release files

0.56.0

2 release files

0.55.0

2 release files

0.54.0

2 release files

0.53.0

2 release files

0.52.0

2 release files

0.51.0

2 release files

0.50.0

2 release files

0.49.0

2 release files

0.48.0

2 release files

0.47.0

2 release files

0.46.0

2 release files

0.45.0

2 release files

0.44.0

2 release files

0.43.0

2 release files

0.42.0

2 release files

0.41.0

2 release files

0.40.0

2 release files

0.39.0

2 release files

0.38.0

2 release files

0.37.0

2 release files

0.36.0

2 release files

0.35.0

2 release files

0.34.0

2 release files

0.33.0

2 release files

0.32.0

2 release files

0.31.0

2 release files

0.30.0

2 release files

0.29.0

2 release files

0.28.0

2 release files

0.27.0

2 release files

0.26.0

2 release files

0.25.0

2 release files

0.24.0

2 release files

0.23.0

2 release files

0.22.0

2 release files

0.21.0

2 release files

0.20.0

2 release files

0.19.0

2 release files

0.18.0

2 release files

0.17.0

2 release files

0.16.0

2 release files

0.15.0

2 release files

0.14.0

2 release files

0.13.0

2 release files

0.10.0

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page