GCP Account Setup
Setting up GCP for tsdevstack deployments. Each environment uses a separate GCP project — repeat these steps for each project.
Service Account Setup
1. Create Service Account
- Go to IAM & Admin > Service Accounts
- Select your project
- Click Create Service Account
- Name:
tsdevstack-deploy(or similar) - Click Create and Continue
2. Grant Initial Roles
Grant these 2 roles to the service account:
In the "Grant this service account access to project" step:
- Click Add Another Role
- Search and add:
Security Admin - Click Add Another Role
- Search and add:
Service Usage Admin - Click Continue then Done
3. Create JSON Key
- Click on the service account you created
- Go to Keys tab
- Click Add Key > Create new key
- Select JSON
- Save the downloaded file
4. Configure Credentials
Create .tsdevstack/.credentials.gcp.json with your key:
The region field is added by the framework — it's not part of the downloaded JSON key. Add it manually to each environment.
Each environment must have a different project_id.
5. Initialize
This automatically:
- Enables all required APIs (14 APIs including Secret Manager, Cloud Run, Cloud SQL, etc.)
- Adds all required roles to the service account (16 additional roles)
- Tests the connection
What Gets Added Automatically
The cloud:init command calls infra:bootstrap, which enables APIs and adds roles.
APIs enabled: Secret Manager, Cloud Run, Artifact Registry, Cloud SQL Admin, Memorystore Redis, Compute Engine, Serverless VPC Access, Service Networking, Cloud Resource Manager, Certificate Manager, Cloud DNS, Cloud Functions, Cloud Build, Cloud Scheduler
Roles added to the service account:
- Secret Manager Admin
- Cloud Run Admin
- Artifact Registry Admin
- Cloud SQL Admin
- Cloud Memorystore Redis Admin
- Compute Admin (VPCs, NEGs, load balancers)
- Serverless VPC Access Admin
- Service Networking Admin
- Storage Admin
- Service Account Admin + User
- Certificate Manager Owner
- DNS Admin
- Cloud Functions Admin + Cloud Build Builder
- Cloud Scheduler Admin
Environment Isolation
Each environment must use a separate GCP project (unique project_id). The framework validates this during cloud:init and rejects duplicate project IDs.
User Secrets via Console
To set user secrets directly in GCP:
- Go to Secret Manager
- Click Create Secret
- Name format:
{project-name}-shared-{KEY}
Or use the CLI:
See Cloud Secrets for details on secret naming and management.
Troubleshooting
Service Deployment Fails
- Go to Cloud Run and check service logs
- Go to Artifact Registry and verify the image exists
- Go to Secret Manager and verify all required secrets exist