Skip to content

Workspace

Connect Google Cloud

Link your Google Cloud project so Elula can build and deploy apps into it.

Elula deploys your apps into your own Google Cloud project. Your apps, databases, images and logs live there, and Google bills you for that usage directly. Elula manages them through a service account you create, and holds no keys.

You connect a project once per workspace. Only workspace owners can connect, reconnect or disconnect it.

Before you start

You need:

  • A Google Cloud project, and its project ID (not its name or number).
  • Billing enabled on that project.
  • A Google account with Owner on the project.
  • The gcloud CLI. Cloud Shell has it already.

Connect

  1. Open Org settings → Cloud and click Connect. New workspaces see this step during setup.
  2. Enter your project ID and pick a region. Your apps run in this region.
  3. Click Copy command.
  4. Paste the command into Cloud Shell or a terminal with gcloud, and press Enter.
  5. Wait for the dashboard to show Connected.

The command looks like this:

curl -fsSL https://<elula-web-address>/bootstrap.sh | bash -s -- \
  --project=acme-prod-4821 \
  --region=asia-southeast1 \
  --token=<one-time-token> \
  --api=https://<elula-api-address>

Regions you can pick:

RegionLocation
asia-southeast1Singapore
us-central1Iowa
europe-west1Belgium
europe-west4Netherlands
australia-southeast1Sydney

The token in the command works once and expires after one hour. If yours has expired, click Refresh command to get a new one.

The script shows a summary of the changes and asks you to confirm. Every step is safe to run again: steps already done are skipped.

Script options

OptionWhat it does
--account=<email>Run setup as this gcloud account. Otherwise the script asks which signed-in account to use.
--no-launch-browserSign in to gcloud without opening a browser (for SSH sessions).
--yes, -ySkip the confirmation prompt.

What the setup command changes

It makes these changes in your project:

  1. Enables the APIs Elula needs: Cloud Run, Cloud Build, Artifact Registry, Cloud SQL Admin, Secret Manager, IAP, Cloud Scheduler, Logging, Cloud Storage, IAM and IAM Credentials.
  2. Creates the elula-deployer service account. Elula acts as this account for every change it makes.
  3. Creates the elula-runtime service account. Your apps run as this account.
  4. Lets elula-deployer act as elula-runtime and as your project's build service account.
  5. Creates an Artifact Registry repository named elula-images and a storage bucket named elula-pages-<project-id> for Pages.
  6. Lets Elula's own service account impersonate elula-deployer. This is a cross-organization IAM grant. No keys are created.
  7. Reports back to Elula, which checks the permissions and marks the workspace Connected.

Roles granted to elula-deployer on the project:

RoleUsed for
roles/run.adminDeploying and managing Cloud Run services and jobs
roles/cloudbuild.builds.editorBuilding images
roles/artifactregistry.adminStoring images
roles/cloudsql.adminManaging databases
roles/secretmanager.adminStoring secrets
roles/iam.securityAdminSetting access on services, including private apps
roles/cloudscheduler.adminJob schedules
roles/logging.viewerReading logs
roles/monitoring.viewerReading metrics
roles/storage.adminStorage buckets

Roles granted to elula-runtime: roles/cloudsql.client and roles/secretmanager.secretAccessor.

If your build service account is the Compute Engine default account, the script also grants it roles/logging.logWriter and roles/artifactregistry.writer, and may enable the Compute Engine API so that account exists.

Check the connection

Org settings → Cloud shows the project, region and status:

StatusMeaning
Not connectedNo project is linked yet.
Waiting for bootstrapThe command hasn't reported back yet.
Preflight failedThe project is reachable, but something Elula needs is missing. The error is shown under the status.
ConnectedElula can deploy into the project.

Click Re-run health check to check the permissions again. New projects can take a few minutes for IAM changes to apply. If the check fails right after setup, wait 2–5 minutes and run it again.

If a permission is missing later, re-run the setup command from Org settings → Cloud. It repairs permissions and skips what is already in place.

Move to a different project

Open Org settings → Cloud → Reconnect, enter the new project ID, and run the new command. The script warns you before it moves the workspace. New deploys go to the new project. Apps already running stay in the old project.

To repair the current connection instead, run the command with the same project ID.

Disconnect

In Org settings → Cloud, click Disconnect Google Cloud and type disconnect to confirm.

  • Your apps and databases stay in your project and keep running.
  • Elula can no longer deploy or manage them.
  • New deploys fail until you connect a project again.

Disconnecting removes the connection on Elula's side. To also remove Elula's access in Google Cloud, delete the elula-deployer service account in your project.

  • Billing: Elula's subscription is separate from your Google Cloud bill.
  • Troubleshooting: setup and permission errors.