Orkestia
Blog
Cloud Connections

Google Cloud (GCP)

Connect a GCP project to your organization and unlock the gcp.* workflow family — Compute, GKE, Cloud Run, Cloud SQL, BigQuery, and billing

The gcp.* family (~100 workflows) covers Compute Engine, GKE, Cloud Run, Cloud SQL, BigQuery, artifact registries, networking, secret management, storage, IAM, and billing/cost queries. All of it runs against your GCP project through a connection you grant.

What the grant is

A GCP connection is a service-account grant on a project you own: you create (or designate) a service account, give it the roles the target workflows need, and hand Orkestia the credential material the prerequisites guide asks for. Orkestia then acts as that service account — its reach is exactly the IAM roles you bound, and detaching the roles or disabling the service account cuts access instantly.

Setting it up

  1. Pick a workflow you want to run (say gcp.gke.* or gcp.run.*) and read its prerequisites — get_workflow_prerequisites over MCP or the dashboard's connection flow. The guide names the exact roles and comes with Orkestia's identity pre-filled where relevant.
  2. In your project: create a dedicated service account (don't reuse a human's), bind only the roles the guide lists, and generate the credential the guide asks for.
  3. Create the connection in Orkestia (org-scoped). Validation runs a read-only check before the connection is usable.
Scope per environment. A service account with roles/owner "to make it work" defeats the model — bind the narrow roles the prerequisites name, and use separate projects/connections for prod vs staging so blast radius follows your own environment boundaries.

What people run on it

  • GKE + Cloud Run deploys — gcp.gke.*, gcp.run.*, and the deploy.* surfaces target GCP compute.
  • Runner capacity — runners provisioned on GCP consume this connection.
  • Billing and cost — gcp.billing.* feeds cost queries and the agent-infra cost sync.
  • Data — gcp.sql.*, gcp.bigquery.*, gcp.storage.* for stateful workloads.

Browse the full family at reference.orkestia.dev/gcp.