Menu
Cloudfunctions.projects.locations.functions.create
Creates a new function. If a function with the given name already exists in the specified project, the long running operation will return `ALREADY_EXISTS` error.
/v1/{location}/functionsUse it in a workflow
- Add a step and choose the Google Cloud Functions connector.
- Pick the Cloudfunctions.projects.locations.functions.create action (under projects).
- Fill in the fields below, then reference the result from later steps as
{{cloudfunctionsProjectsLocationsFunctionsCreate.response.data}}.
Request
Path parameters
locationstringrequiredRequired. The project and location in which the function should be created, specified in the format `projects/*/locations/*`
Query parameters
$.xgafvstringV1 error format.
One of12
access_tokenstringOAuth access token.
altstringData format for response.
One ofjsonmediaproto
callbackstringJSONP
fieldsstringSelector specifying which fields to include in a partial response.
keystringAPI key. Your API key identifies your project and provides you with API access, quota, and reports. Required unless you provide an OAuth 2.0 token.
oauth_tokenstringOAuth 2.0 token for the current user.
prettyPrintbooleanReturns response with indentations and line breaks.
quotaUserstringAvailable to use for quota purposes for server-side applications. Can be any arbitrary string assigned to a user, but should not exceed 40 characters.
upload_protocolstringUpload protocol for media (e.g. "raw", "multipart").
uploadTypestringLegacy upload protocol for media (e.g. "media", "multipart").
Request body
Enter the body as JSON in the step's Body field.
availableMemoryMbinteger (int32)The amount of memory in MB available for a function. Defaults to 256MB.
buildEnvironmentVariablesobjectBuild environment variables that shall be available during build time.
buildIdstringOutput only. The Cloud Build ID of the latest successful deployment of the function.
buildNamestringOutput only. The Cloud Build Name of the function deployment. `projects//locations//builds/`.
buildWorkerPoolstringName of the Cloud Build Custom Worker Pool that should be used to build the function. The format of this field is `projects/{project}/locations/{region}/workerPools/{workerPool}` where `{project}` and `{region}` are the project id and region respectively where the worker pool is defined and `{workerPool}` is the short name of the worker pool. If the project id is not the same as the function, then the Cloud Functions Service Agent (`service-@gcf-admin-robot.iam.gserviceaccount.com`) must be granted the role Cloud Build Custom Workers Builder (`roles/cloudbuild.customworkers.builder`) in the project.
descriptionstringUser-provided description of a function.
dockerRegistrystringDocker Registry to use for this deployment. If `docker_repository` field is specified, this field will be automatically set as `ARTIFACT_REGISTRY`. If unspecified, it currently defaults to `CONTAINER_REGISTRY`. This field may be overridden by the backend for eligible deployments.
One ofDOCKER_REGISTRY_UNSPECIFIEDCONTAINER_REGISTRYARTIFACT_REGISTRY
dockerRepositorystringUser managed repository created in Artifact Registry optionally with a customer managed encryption key. If specified, deployments will use Artifact Registry. If unspecified and the deployment is eligible to use Artifact Registry, GCF will create and use a repository named 'gcf-artifacts' for every deployed region. This is the repository to which the function docker image will be pushed after it is built by Cloud Build. It must match the pattern `projects/{project}/locations/{location}/repositories/{repository}`. Cross-project repositories are not supported. Cross-location repositories are not supported. Repository format must be 'DOCKER'.
entryPointstringThe name of the function (as defined in source code) that will be executed. Defaults to the resource name suffix, if not specified. For backward compatibility, if function with given name is not found, then the system will try to use function named "function". For Node.js this is name of a function exported by the module specified in `source_location`.
environmentVariablesobjectEnvironment variables that shall be available during function execution.
eventTriggerobjectDescribes EventTrigger, used to request events be sent from another service.
eventTypestringRequired. The type of event to observe. For example: `providers/cloud.storage/eventTypes/object.change` and `providers/cloud.pubsub/eventTypes/topic.publish`. Event types match pattern `providers/*/eventTypes/*.*`. The pattern contains: 1. namespace: For example, `cloud.storage` and `google.firebase.analytics`. 2. resource type: The type of resource on which event occurs. For example, the Google Cloud Storage API includes the type `object`. 3. action: The action that generates the event. For example, action for a Google Cloud Storage Object is 'change'. These parts are lower case.
failurePolicyobject1 fieldsDescribes the policy in case of function's execution failure. If empty, then defaults to ignoring failures (i.e. not retrying them).
resourcestringRequired. The resource(s) from which to observe events, for example, `projects/_/buckets/myBucket`. Not all syntactically correct values are accepted by all services. For example: 1. The authorization model must support it. Google Cloud Functions only allows EventTriggers to be deployed that observe resources in the same project as the `CloudFunction`. 2. The resource type must match the pattern expected for an `event_type`. For example, an `EventTrigger` that has an `event_type` of "google.pubsub.topic.publish" should have a resource that matches Google Cloud Pub/Sub topics. Additionally, some services may support short names when creating an `EventTrigger`. These will always be returned in the normalized "long" format. See each *service's* documentation for supported formats.
servicestringThe hostname of the service that should be observed. If no string is provided, the default service implementing the API will be used. For example, `storage.googleapis.com` is the default for all event types in the `google.storage` namespace.
httpsTriggerobjectDescribes HttpsTrigger, could be used to connect web hooks to function.
securityLevelstringThe security level for the function.
One ofSECURITY_LEVEL_UNSPECIFIEDSECURE_ALWAYSSECURE_OPTIONAL
urlstringOutput only. The deployed url for the function.
ingressSettingsstringThe ingress settings for the function, controlling what traffic can reach it.
One ofINGRESS_SETTINGS_UNSPECIFIEDALLOW_ALLALLOW_INTERNAL_ONLYALLOW_INTERNAL_AND_GCLB
kmsKeyNamestringResource name of a KMS crypto key (managed by the user) used to encrypt/decrypt function resources. It must match the pattern `projects/{project}/locations/{location}/keyRings/{key_ring}/cryptoKeys/{crypto_key}`. If specified, you must also provide an artifact registry repository using the `docker_repository` field that was created with the same KMS crypto key. The following service accounts need to be granted the role 'Cloud KMS CryptoKey Encrypter/Decrypter (roles/cloudkms.cryptoKeyEncrypterDecrypter)' on the Key/KeyRing/Project/Organization (least access preferred). 1. Google Cloud Functions service account (service-{project_number}@gcf-admin-robot.iam.gserviceaccount.com) - Required to protect the function's image. 2. Google Storage service account (service-{project_number}@gs-project-accounts.iam.gserviceaccount.com) - Required to protect the function's source code. If this service account does not exist, deploying a function without a KMS key or retrieving the service agent name provisions it. For more information, see https://cloud.google.com/storage/docs/projects#service-agents and https://cloud.google.com/storage/docs/getting-service-agent#gsutil. Google Cloud Functions delegates access to service agents to protect function resources in internal projects that are not accessible by the end user.
labelsobjectLabels associated with this Cloud Function.
maxInstancesinteger (int32)The limit on the maximum number of function instances that may coexist at a given time. In some cases, such as rapid traffic surges, Cloud Functions may, for a short period of time, create more instances than the specified max instances limit. If your function cannot tolerate this temporary behavior, you may want to factor in a safety margin and set a lower max instances value than your function can tolerate. See the [Max Instances](https://cloud.google.com/functions/docs/max-instances) Guide for more details.
minInstancesinteger (int32)A lower bound for the number function instances that may coexist at a given time.
namestringA user-defined name of the function. Function names must be unique globally and match pattern `projects/*/locations/*/functions/*`
networkstringThe VPC Network that this cloud function can connect to. It can be either the fully-qualified URI, or the short name of the network resource. If the short network name is used, the network must belong to the same project. Otherwise, it must belong to a project within the same organization. The format of this field is either `projects/{project}/global/networks/{network}` or `{network}`, where `{project}` is a project id where the network is defined, and `{network}` is the short name of the network. This field is mutually exclusive with `vpc_connector` and will be replaced by it. See [the VPC documentation](https://cloud.google.com/compute/docs/vpc) for more information on connecting Cloud projects.
runtimestringThe runtime in which to run the function. Required when deploying a new function, optional when updating an existing function. For a complete list of possible choices, see the [`gcloud` command reference](https://cloud.google.com/sdk/gcloud/reference/functions/deploy#--runtime).
secretEnvironmentVariablesarray<object>Secret environment variables configuration.
keystringName of the environment variable.
projectIdstringProject identifier (preferrably project number but can also be the project ID) of the project that contains the secret. If not set, it will be populated with the function's project assuming that the secret exists in the same project as of the function.
secretstringName of the secret in secret manager (not the full resource name).
versionstringVersion of the secret (version number or the string 'latest'). It is recommended to use a numeric version for secret environment variables as any updates to the secret value is not reflected until new instances start.
secretVolumesarray<object>Secret volumes configuration.
mountPathstringThe path within the container to mount the secret volume. For example, setting the mount_path as `/etc/secrets` would mount the secret value files under the `/etc/secrets` directory. This directory will also be completely shadowed and unavailable to mount any other secrets. Recommended mount paths: /etc/secrets Restricted mount paths: /cloudsql, /dev/log, /pod, /proc, /var/log
projectIdstringProject identifier (preferrably project number but can also be the project ID) of the project that contains the secret. If not set, it will be populated with the function's project assuming that the secret exists in the same project as of the function.
secretstringName of the secret in secret manager (not the full resource name).
versionsarray<object>2 fieldsList of secret versions to mount for this secret. If empty, the `latest` version of the secret will be made available in a file named after the secret under the mount point.
serviceAccountEmailstringThe email of the function's service account. If empty, defaults to `{project_id}@appspot.gserviceaccount.com`.
sourceArchiveUrlstringThe Google Cloud Storage URL, starting with `gs://`, pointing to the zip archive which contains the function.
sourceRepositoryobjectDescribes SourceRepository, used to represent parameters related to source repository where a function is hosted.
deployedUrlstringOutput only. The URL pointing to the hosted repository where the function were defined at the time of deployment. It always points to a specific commit in the format described above.
urlstringThe URL pointing to the hosted repository where the function is defined. There are supported Cloud Source Repository URLs in the following formats: To refer to a specific commit: `https://source.developers.google.com/projects/*/repos/*/revisions/*/paths/*` To refer to a moveable alias (branch): `https://source.developers.google.com/projects/*/repos/*/moveable-aliases/*/paths/*` In particular, to refer to HEAD use `master` moveable alias. To refer to a specific fixed alias (tag): `https://source.developers.google.com/projects/*/repos/*/fixed-aliases/*/paths/*` You may omit `paths/*` if you want to use the main directory.
sourceTokenstringInput only. An identifier for Firebase function sources. Disclaimer: This field is only supported for Firebase function deployments.
sourceUploadUrlstringThe Google Cloud Storage signed URL used for source uploading, generated by calling [google.cloud.functions.v1.GenerateUploadUrl]. The signature is validated on write methods (Create, Update) The signature is stripped from the Function object on read methods (Get, List)
statusstringOutput only. Status of the function deployment.
One ofCLOUD_FUNCTION_STATUS_UNSPECIFIEDACTIVEOFFLINEDEPLOY_IN_PROGRESSDELETE_IN_PROGRESSUNKNOWN
timeoutstring (google-duration)The function execution timeout. Execution is considered failed and can be terminated if the function is not completed at the end of the timeout period. Defaults to 60 seconds.
updateTimestring (google-datetime)Output only. The last update timestamp of a Cloud Function.
versionIdstring (int64)Output only. The version identifier of the Cloud Function. Each deployment attempt results in a new version of a function being created.
vpcConnectorstringThe VPC Network Connector that this cloud function can connect to. It can be either the fully-qualified URI, or the short name of the network connector resource. The format of this field is `projects/*/locations/*/connectors/*` This field is mutually exclusive with `network` field and will eventually replace it. See [the VPC documentation](https://cloud.google.com/compute/docs/vpc) for more information on connecting Cloud projects.
vpcConnectorEgressSettingsstringThe egress settings for the connector, controlling what traffic is diverted through it.
One ofVPC_CONNECTOR_EGRESS_SETTINGS_UNSPECIFIEDPRIVATE_RANGES_ONLYALL_TRAFFIC
{
"availableMemoryMb": 0,
"buildEnvironmentVariables": {},
"buildId": "string",
"buildName": "string",
"buildWorkerPool": "string",
"description": "string",
"dockerRegistry": "DOCKER_REGISTRY_UNSPECIFIED",
"dockerRepository": "string",
"entryPoint": "string",
"environmentVariables": {},
"eventTrigger": {
"eventType": "string",
"failurePolicy": {
"retry": {}
},
"resource": "string",
"service": "string"
},
"httpsTrigger": {
"securityLevel": "SECURITY_LEVEL_UNSPECIFIED",
"url": "string"
}
}
Response
Returns 200 with an object. Read it in later steps with {{cloudfunctionsProjectsLocationsFunctionsCreate.response.data.<field>}}.
donebooleanIf the value is `false`, it means the operation is still in progress. If `true`, the operation is completed, and either `error` or `response` is available.
errorobjectThe `Status` type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by [gRPC](https://github.com/grpc). Each `Status` message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the [API Design Guide](https://cloud.google.com/apis/design/errors).
codeinteger (int32)The status code, which should be an enum value of google.rpc.Code.
detailsarray<object>A list of messages that carry the error details. There is a common set of message types for APIs to use.
messagestringA developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the google.rpc.Status.details field, or localized by the client.
metadataobjectService-specific metadata associated with the operation. It typically contains progress information and common metadata such as create time. Some services might not provide such metadata. Any method that returns a long-running operation should document the metadata type, if any.
namestringThe server-assigned name, which is only unique within the same service that originally returns it. If you use the default HTTP mapping, the `name` should be a resource name ending with `operations/{unique_id}`.
responseobjectThe normal response of the operation in case of success. If the original method returns no data on success, such as `Delete`, the response is `google.protobuf.Empty`. If the original method is standard `Get`/`Create`/`Update`, the response should be the resource. For other methods, the response should have the type `XxxResponse`, where `Xxx` is the original method name. For example, if the original method name is `TakeSnapshot()`, the inferred response type is `TakeSnapshotResponse`.
{
"done": false,
"error": {
"code": 0,
"details": [
{}
],
"message": "string"
},
"metadata": {},
"name": "string",
"response": {}
}
Need more? See the Google Cloud Functions guide for connection setup and behaviour shared by every action.