Quickstart: Deploy to Cloud Run

This page shows you how to use Cloud Run to deploy a sample container.

Before you begin

  1. In the Cloud de Confiance console, on the project selector page, select or create a Cloud de Confiance project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  2. If you're using an existing project for this guide, verify that you have the permissions required to complete this guide. If you created a new project, then you already have the required permissions.

  3. Verify that billing is enabled for your Cloud de Confiance project.

  4. Review Cloud Run pricing or estimate costs with the pricing calculator.

Required roles

To get the permissions that you need to complete this quickstart, ask your administrator to grant you the following IAM roles:

For more information about granting roles, see Manage access to projects, folders, and organizations.

You might also be able to get the required permissions through custom roles or other predefined roles.

To configure Direct VPC egress, you must also grant additional roles so that Cloud Run has access to the VPC network.

Create a VPC Network

If you don't already have a VPC network in your project, create one.

Before you connect your service to a VPC network, review the following IP address configuration sections:

Optional: Configure network address translation (NAT)

If your service needs to access the public internet, you must configure Cloud NAT before you deploy your service. See instructions for configuring Cloud NAT in Static outbound IP address.

If your service only needs to access private addresses and Google APIs, you don't need to configure Cloud NAT.

Deploying the sample container

To deploy a container, follow these steps:

  1. In the Cloud de Confiance console, go to the Cloud Run page:

    Go to Cloud Run

  2. Select Services from the menu, and click Deploy container.

  3. In the Container image URL field, enter a container image URL.

  4. In the Service name field, enter a service name or use the default value.

  5. In the Region list, use the default value.

  6. In the Authentication section, select Allow public access.

  7. In the Networking tab, click Connect to a VPC for outbound traffic.

  8. Click Send traffic directly to a VPC.

    1. In the Network field, select the VPC network that you want to send traffic to.

    2. In the Subnet field, select the subnet where your service receives IP addresses from. You can deploy multiple services on the same subnet.

    3. Optional: Enter the names of the network tags that you want to associate with your service or services. Network tags are specified at the revision-level. Each service revision can have different network tags, such as network-tag-2.

  9. For Traffic routing, ensure the Route all traffic to the VPC option is selected. This send all outbound traffic through the VPC network.

    To access the internet in Cloud de Confiance, you must use Direct VPC egress and Cloud NAT.

  10. Click Create, and then wait for the container to deploy to Cloud Run. After deployment, the container's URL is displayed next to the text URL:.

  11. To view the running container, click Copy to clipboard to copy its URL, and then paste the URL into your browser's address bar.

    If you are under a domain restriction organization policy restricting unauthenticated invocations for your project, you will need to access your deployed service as described under Testing private services.

Cloud Run locations

Cloud Run is regional, which means the infrastructure that runs your Cloud Run services is located in a specific region and is managed by Google to be redundantly available across all the zones within that region.

Meeting your latency, availability, or durability requirements are primary factors for selecting the region where your Cloud Run services are run. You can generally select the region nearest to your users but you should consider the location of the other Cloud de Confiance products that are used by your Cloud Run service. Using Cloud de Confiance products together across multiple locations can affect your service's latency as well as cost.

Cloud Run is available in the following regions:

Subject to Tier 1 pricing

  • asia-east1 (Taiwan)
  • asia-northeast1 (Tokyo)
  • asia-northeast2 (Osaka)
  • asia-south1 (Mumbai, India)
  • asia-southeast3 (Bangkok)
  • europe-north1 (Finland) leaf icon Low CO2
  • europe-north2 (Stockholm) leaf icon Low CO2
  • europe-southwest1 (Madrid) leaf icon Low CO2
  • europe-west1 (Belgium) leaf icon Low CO2
  • europe-west4 (Netherlands) leaf icon Low CO2
  • europe-west8 (Milan)
  • europe-west9 (Paris) leaf icon Low CO2
  • me-west1 (Tel Aviv)
  • northamerica-south1 (Mexico)
  • us-central1 (Iowa) leaf icon Low CO2
  • us-east1 (South Carolina)
  • us-east4 (Northern Virginia)
  • us-east5 (Columbus)
  • us-south1 (Dallas) leaf icon Low CO2
  • us-west1 (Oregon) leaf icon Low CO2

Subject to Tier 2 pricing

  • africa-south1 (Johannesburg)
  • asia-east2 (Hong Kong)
  • asia-northeast3 (Seoul, South Korea)
  • asia-southeast1 (Singapore)
  • asia-southeast2 (Jakarta)
  • asia-south2 (Delhi, India)
  • australia-southeast1 (Sydney)
  • australia-southeast2 (Melbourne)
  • europe-central2 (Warsaw, Poland)
  • europe-west10 (Berlin)
  • europe-west12 (Turin)
  • europe-west2 (London, UK) leaf icon Low CO2
  • europe-west3 (Frankfurt, Germany)
  • europe-west6 (Zurich, Switzerland) leaf icon Low CO2
  • me-central1 (Doha)
  • me-central2 (Dammam)
  • northamerica-northeast1 (Montreal) leaf icon Low CO2
  • northamerica-northeast2 (Toronto) leaf icon Low CO2
  • southamerica-east1 (Sao Paulo, Brazil) leaf icon Low CO2
  • southamerica-west1 (Santiago, Chile) leaf icon Low CO2
  • us-west2 (Los Angeles)
  • us-west3 (Salt Lake City)
  • us-west4 (Las Vegas)

If you already created a Cloud Run service, you can view the region in the Cloud Run dashboard in the Cloud de Confiance console.

Cloud Run automatically scales your container instances based on demand, and you only pay for the CPU, memory, and networking consumed during request processing.

Clean up

To avoid additional charges to your Cloud de Confiance by S3NS account, delete all the resources you deployed with this quickstart.

Delete your repository

Cloud Run doesn't charge you when your deployed service isn't in use. However, you might still be charged for storing the container image in Artifact Registry. To delete Artifact Registry repositories, follow the steps in Delete repositories in the Artifact Registry documentation.

Delete your service

Cloud Run services don't incur costs until they receive requests. To delete your Cloud Run service, follow one of these steps:

Console

To delete a service:

  1. In the Cloud de Confiance by S3NS console, go to the Cloud Run Services page:

    Go to Cloud Run

  2. Locate the service you want to delete in the services list, and click its checkbox to select it.

  3. Click Delete. This deletes all revisions of the service.

gcloud

To delete a service, run the following command:

gcloud run services delete SERVICE --region REGION

Replace the following:

  • SERVICE: name of your service.
  • REGION: Cloud de Confiance region of the service.

Delete your test project

Deleting your Cloud de Confiance project stops billing for all resources in that project. To release all Cloud de Confiance by S3NS resources in your project, follow these steps:

  1. In the Cloud de Confiance console, go to the Manage resources page.

    Go to Manage resources

  2. In the project list, select the project that you want to delete, and then click Delete.
  3. In the dialog, type the project ID, and then click Shut down to delete the project.

What's next

To learn how to build a container from code source, push to Artifact Registry, and deploy, see: