Infra Timelapse runs as a finite Cloud Run Job. Cloud Scheduler currently
invokes it daily at 03:00 in Pacific/Honolulu for short-term schedule
validation. Each execution stores images and a SHA-256 manifest in a private
Cloud Storage bucket.
- Google Cloud CLI installed and authenticated
gcloud config set project infra-timelapsecompleted- billing enabled on the selected project
- permission to enable APIs, create service accounts, and add the listed IAM bindings
From the repository root:
bash deploy/setup_gcp.shThe script prints its exact resource plan and makes no changes unless you type
deploy. If the Secret Manager secret has no enabled version, it asks for the
Google Maps API key using hidden terminal input. It is safe to run again to
update the container and job configuration.
Defaults can be overridden for one invocation:
REGION=us-west1 BUCKET_NAME=my-private-bucket bash deploy/setup_gcp.shThe setup script creates the schedule without triggering an immediate run. Test the complete path explicitly:
gcloud run jobs execute infra-timelapse-capture \
--region us-west1 \
--project infra-timelapse \
--wait
gcloud storage ls gs://infra-timelapse-infra-timelapse-images/manifests/A full run should report 204 uploaded images. Objects are stored under a unique UTC run identifier, so later captures do not overwrite earlier captures.
Each Static Maps request is retried up to four times for network failures and
HTTP 429, 500, 502, 503, or 504 responses, using exponential backoff
with jitter. If an individual target still fails, the run continues, uploads
the successful captures, and publishes a partial_success manifest containing
the failed target ID, name, status code, and attempt count. The job fails only
when every selected target fails or a job-level operation such as storage
uploading fails.
The setup creates or updates:
- an Artifact Registry Docker repository
- a private Cloud Storage bucket with public-access prevention
- a Secret Manager secret for the Maps API key
- a runtime service account with bucket object access and secret access
- a scheduler service account with permission to execute only the Cloud Run job
- the Cloud Run job and Cloud Scheduler HTTP job
The current test schedule expression is 0 3 * * *, which runs daily at 03:00
in Pacific/Honolulu. To restore the twice-monthly cadence without changing
the script default, deploy with SCHEDULE="0 3 1,15 * *". For a weekly Sunday
capture, use SCHEDULE="0 3 * * 0".
bash deploy/cleanup_gcp.shThe cleanup script has a separate confirmation gate. It preserves the bucket and secret deliberately; deleting either could destroy capture history or a credential version.