Google Cloud Functions

Required attributes

  • GCP Project Id — the GCP project that owns the functions.
  • GCP Location — the region the functions are deployed in (e.g., us-central1).

There is no per-platform function attribute: functions are discovered as jobs from the project's Cloud Functions listing and invoked by their HTTP endpoint.

Authentication methods

  • Service Account Key — Google Service Account Key (a JSON service account key). Long-lived; rotate manually and store in a Secret Vault.
  • Application Default Credentials — uses the host environment's ADC.
  • Workload Identity Federation ⭐ (recommended) — Google Workload Identity Provider, optional Google Service Account Email (impersonated after the token exchange). No JSON keys.
  • Impersonated Service Account — delegate from a source identity (Google Source Service Account Key or host ADC) to the target Google Service Account Email.

Permissions checklist

  • The invoking identity must hold Cloud Functions Invoker (roles/cloudfunctions.invoker) on the function (Gen 1) or Cloud Run Invoker (roles/run.invoker) on the underlying Cloud Run service (Gen 2).
  • For Workload Identity Federation configure the Pool/Provider trust to match the Polysync host identity.

Supported jobs