Workspace
Connect Google Cloud
Link your Google Cloud project so Elula can build and deploy apps into it.
Elula deploys your apps into your own Google Cloud project. Your apps, databases, images and logs live there, and Google bills you for that usage directly. Elula manages them through a service account you create, and holds no keys.
You connect a project once per workspace. Only workspace owners can connect, reconnect or disconnect it.
Before you start
You need:
- A Google Cloud project, and its project ID (not its name or number).
- Billing enabled on that project.
- A Google account with Owner on the project.
- The
gcloudCLI. Cloud Shell has it already.
Connect
- Open Org settings → Cloud and click Connect. New workspaces see this step during setup.
- Enter your project ID and pick a region. Your apps run in this region.
- Click Copy command.
- Paste the command into Cloud Shell or a terminal with
gcloud, and press Enter. - Wait for the dashboard to show Connected.
The command looks like this:
curl -fsSL https://<elula-web-address>/bootstrap.sh | bash -s -- \ --project=acme-prod-4821 \ --region=asia-southeast1 \ --token=<one-time-token> \ --api=https://<elula-api-address>
Regions you can pick:
| Region | Location |
|---|---|
asia-southeast1 | Singapore |
us-central1 | Iowa |
europe-west1 | Belgium |
europe-west4 | Netherlands |
australia-southeast1 | Sydney |
The token in the command works once and expires after one hour. If yours has expired, click Refresh command to get a new one.
The script shows a summary of the changes and asks you to confirm. Every step is safe to run again: steps already done are skipped.
Script options
| Option | What it does |
|---|---|
--account=<email> | Run setup as this gcloud account. Otherwise the script asks which signed-in account to use. |
--no-launch-browser | Sign in to gcloud without opening a browser (for SSH sessions). |
--yes, -y | Skip the confirmation prompt. |
What the setup command changes
It makes these changes in your project:
- Enables the APIs Elula needs: Cloud Run, Cloud Build, Artifact Registry, Cloud SQL Admin, Secret Manager, IAP, Cloud Scheduler, Logging, Cloud Storage, IAM and IAM Credentials.
- Creates the
elula-deployerservice account. Elula acts as this account for every change it makes. - Creates the
elula-runtimeservice account. Your apps run as this account. - Lets
elula-deployeract aselula-runtimeand as your project's build service account. - Creates an Artifact Registry repository named
elula-imagesand a storage bucket namedelula-pages-<project-id>for Pages. - Lets Elula's own service account impersonate
elula-deployer. This is a cross-organization IAM grant. No keys are created. - Reports back to Elula, which checks the permissions and marks the workspace Connected.
Roles granted to elula-deployer on the project:
| Role | Used for |
|---|---|
roles/run.admin | Deploying and managing Cloud Run services and jobs |
roles/cloudbuild.builds.editor | Building images |
roles/artifactregistry.admin | Storing images |
roles/cloudsql.admin | Managing databases |
roles/secretmanager.admin | Storing secrets |
roles/iam.securityAdmin | Setting access on services, including private apps |
roles/cloudscheduler.admin | Job schedules |
roles/logging.viewer | Reading logs |
roles/monitoring.viewer | Reading metrics |
roles/storage.admin | Storage buckets |
Roles granted to elula-runtime: roles/cloudsql.client and roles/secretmanager.secretAccessor.
If your build service account is the Compute Engine default account, the script also grants it roles/logging.logWriter and roles/artifactregistry.writer, and may enable the Compute Engine API so that account exists.
Check the connection
Org settings → Cloud shows the project, region and status:
| Status | Meaning |
|---|---|
| Not connected | No project is linked yet. |
| Waiting for bootstrap | The command hasn't reported back yet. |
| Preflight failed | The project is reachable, but something Elula needs is missing. The error is shown under the status. |
| Connected | Elula can deploy into the project. |
Click Re-run health check to check the permissions again. New projects can take a few minutes for IAM changes to apply. If the check fails right after setup, wait 2–5 minutes and run it again.
If a permission is missing later, re-run the setup command from Org settings → Cloud. It repairs permissions and skips what is already in place.
Move to a different project
Open Org settings → Cloud → Reconnect, enter the new project ID, and run the new command. The script warns you before it moves the workspace. New deploys go to the new project. Apps already running stay in the old project.
To repair the current connection instead, run the command with the same project ID.
Disconnect
In Org settings → Cloud, click Disconnect Google Cloud and type disconnect to confirm.
- Your apps and databases stay in your project and keep running.
- Elula can no longer deploy or manage them.
- New deploys fail until you connect a project again.
Disconnecting removes the connection on Elula's side. To also remove Elula's access in Google Cloud, delete the elula-deployer service account in your project.
Related
- Billing: Elula's subscription is separate from your Google Cloud bill.
- Troubleshooting: setup and permission errors.