Google Cloud Functions
Required attributes
- GCP Project Id — the GCP project that owns the functions.
- GCP Location — the region the functions are deployed in
(e.g.,
us-central1).
There is no per-platform function attribute: functions are discovered as
jobs from the project's Cloud Functions listing and invoked by their
HTTP endpoint.
Authentication methods
- Service Account Key — Google Service Account Key (a JSON service
account key). Long-lived; rotate manually and store in a Secret Vault.
- Application Default Credentials — uses the host environment's ADC.
- Workload Identity Federation ⭐ (recommended) — Google Workload
Identity Provider, optional Google Service Account Email (impersonated
after the token exchange). No JSON keys.
- Impersonated Service Account — delegate from a source identity
(Google Source Service Account Key or host ADC) to the target
Google Service Account Email.
Permissions checklist
- The invoking identity must hold Cloud Functions Invoker
(
roles/cloudfunctions.invoker) on the function (Gen 1) or Cloud Run
Invoker (roles/run.invoker) on the underlying Cloud Run service
(Gen 2).
- For Workload Identity Federation configure the Pool/Provider trust to
match the Polysync host identity.
Supported jobs