Skip to content

Help

Troubleshooting

Common error messages, what causes them, and how to fix them.

Find the message you're seeing. Each entry gives the cause and the fix. Messages in the CLI and the dashboard use the same wording unless noted.

Google Cloud setup

"Your organization's cloud isn't connected yet."

In the dashboard or deploy log this reads: "Google Cloud is not connected for this organization (status: …). Connect it in Organization settings, then redeploy."

Why: the workspace has no working Google Cloud connection, so there is nowhere to deploy.

Fix: a workspace owner connects a project in Org settings → Cloud. If the status is "preflight_failed", see the next entries. See Connect Google Cloud.

"This setup token isn't valid — it has already been used, or was replaced."

Why: setup tokens work once. The command was already run, or a newer command replaced it.

Fix: copy a fresh command from Org settings → Cloud and run that. Nothing was changed in your project.

"This setup token has expired (tokens last 1 hour)."

Why: the command was copied more than an hour ago.

Fix: click Refresh command, copy it and run it again. Steps that already finished are skipped.

"Billing is not enabled for project …"

Why: Google Cloud won't enable APIs on a project without a billing account.

Fix: link a billing account to the project in the Google Cloud console, then re-run the command.

"Can't access Google Cloud project '…' as …"

Why: the project ID is wrong, or the signed-in gcloud account isn't an Owner of the project.

Fix: check the ID with gcloud projects list (use the ID, not the display name). Sign in as an Owner with gcloud auth login, or pass --account=<owner-email>. A brand-new project can take a minute to appear.

"Your organization policy (iam.allowedPolicyMemberDomains) blocks granting access…"

Why: your Google Cloud organization only allows IAM grants to accounts inside it. Setup needs to grant Elula's service account access to elula-deployer.

Fix: ask a Google Cloud organization admin to allow Elula's service account (the script prints it) for your project, then re-run the command. A similar message names other blocking policies, such as one that disables service account creation.

"Setup finished, but Elula's permission check didn't pass yet"

Why: IAM changes on a new project can take several minutes to apply everywhere.

Fix: wait 2–5 minutes, then click Re-run health check in Org settings → Cloud. Don't re-run the setup command: its token is already used.

GitHub

"The Elula GitHub App is installed on … but can't see …"

The App is installed on that account but was only given some repositories. elula init opens the installation's settings on GitHub and prints the link. Under Repository access, add the repo (or choose All repositories) and save. elula init carries on by itself once GitHub reports the change. On an organization, an owner of the organization may need to approve it.

"The Elula GitHub App isn't installed on …"

elula init opens GitHub's install page for that account. Install the App, give it the repo, and elula init carries on. If nothing opens in your browser, open the printed link yourself.

Deploys

"Elula's deployer account is not allowed to act as a service account…"

The message ends with "missing roles/iam.serviceAccountUser on it". A related message is "Elula's deployer account is missing a permission in your Google Cloud project."

Why: a permission Elula needs in your project was removed or never applied.

Fix: re-run the setup command from Org settings → Cloud. It is safe to run again and repairs permissions. Then redeploy.

"Build never started and expired in the queue" or "Build was still waiting to start after 10 minutes and was cancelled"

Why: this usually means Elula's deployer account can't act as the build service account in your project.

Fix: re-run the setup command from Org settings → Cloud, then redeploy.

"Build failed with status: FAILURE — …"

Why: your build step failed, for example a failing install, a compile error or a missing file.

Fix: read the build logs with elula logs, or open the logs link in the message. Fix the error in your code and push or redeploy. In a monorepo, check the app's root directory and Docker context. See Monorepos and Frameworks and Dockerfiles.

The container failed to start and listen on the port defined by the PORT environment variable

This message comes from Google Cloud Run.

Why: your app didn't start, or it listens on a different port than the one Cloud Run sends traffic to.

Fix: make your server listen on 0.0.0.0 and the port in the PORT environment variable. If your app must use a fixed port, tell Elula with elula scale --port <port>. Check elula runtime-logs for a crash on startup. See Deploy a web app or API.

"A deployment is already in progress."

Why: only one deployment runs at a time for an app.

Fix: follow it with elula logs, or cancel it and start a new one with elula deploy --force.

Billing

"Subscribe to deploy. Apps that are already running keep running." or "Subscribe to create apps."

Why: the workspace has no active subscription. It was never started, or it was cancelled and the period has ended.

Fix: an owner or billing member subscribes on the Billing page. See Billing.

"Payment failed, so deploys are paused. Update your card on the Billing page."

Why: a payment failed more than 7 days ago.

Fix: an owner or billing member clicks Update card on the Billing page. Deploys work again once the payment succeeds.

"You're at 5 of 5 apps on your plan…" or "You have … apps; your plan includes 5. Delete one to deploy again."

Why: the plan includes up to 5 apps.

Fix: delete an app you don't need.

"Custom domains need an active subscription."

Why: custom domains are part of the Starter plan.

Fix: subscribe on the Billing page.

Access and team

"Your workspace's team domain isn't set up yet, so apps can't be private."

Why: private apps need a verified team domain.

Fix: a workspace owner adds and verifies it in Org settings → Access, or make the app public. See Private and public apps.

"Only org owners can create a public app…" or "Making this app public needs an org owner's or admin's approval."

Why: your workspace requires approval for members to make apps public.

Fix: run elula access request-public, or use the app's Settings. An owner or admin approves it on the Approvals page. If the request is refused with "Only owners and admins can make apps public in this workspace.", members can't make apps public at all; ask an owner or admin to do it.

A private app shows a Google permission screen

Why: either you're signed in with a Google account that isn't on the team domain, or the app was deployed for the first time in the last couple of minutes.

Fix: sign in with your team domain account. Right after a first deploy, wait 1–2 minutes and refresh.

"Deployed, but access for @… could not be granted."

Why: Google rejected the grant for your team domain. Google only accepts domains that are Google Workspace or Cloud Identity domains.

Fix: check that your team domain is a Google Workspace or Cloud Identity domain, then redeploy.

"TXT record not found yet — DNS can take a few minutes to propagate."

Why: Elula couldn't find the _elula-verify.<domain> TXT record yet.

Fix: check the record name and value at your DNS provider, wait a few minutes, and verify again.

"This invite is for … Sign in with that account to accept it."

Why: the invite was sent to a specific email, and you're signed in with a different Google account.

Fix: sign out and sign in with the invited account, or ask for a new invite. "Invite has expired" and "Invite already used" mean you need a new link; an owner or admin can resend it.

"You don't have permission to do this (requires …)."

Why: your role doesn't include that action. For example, org settings are owner-only.

Fix: ask an owner. See Team and roles.

CLI and account

"Your session has expired or is invalid. Run: elula login"

Fix: run elula login.

"This workspace has been deleted."

Why: an owner deleted the workspace.

Fix: an owner can restore it within 7 days from the banner in the dashboard. See Delete a workspace.