Memory hook: Revision receives; identity authorizes; retries repeat.
Must remember
Cloud Run runs containerized services without managing a VM fleet. Services receive requests; Jobs run finite tasks. A revision is an immutable deployment configuration. Split traffic between revisions for controlled release and rollback, and distinguish deploying a revision from sending it production traffic.
Scale and concurrency settings affect latency, cost and downstream connection pressure. Minimum instances reduce cold-start exposure while keeping capacity allocated; maximum instances can protect a backend but do not replace admission control or guarantee unlimited availability. Keep request handlers stateless and externalize durable state.
Cloud Run functions is the current function-oriented experience associated with the older Cloud Functions name. Select generation/runtime/event support deliberately. Eventarc routes supported events to targets; Pub/Sub decouples message producers and subscribers. Cloud Storage object events can trigger processing. Match region, trigger identity, target invocation permissions and event schema.
Design handlers for retries and duplicate delivery. Persist an idempotency key/result or make the operation naturally repeatable. A successful HTTP response acknowledges work; returning success before durable completion can lose business processing. Timeouts and retry policies must match the work and poison-event handling.
Invocation identity and runtime identity are distinct: one calls the service, the other determines what code may access. Restrict ingress and use authenticated invocation where appropriate. VPC egress configuration permits access to private dependencies; it does not automatically make all inbound requests private.
For a rollout issue, inspect the revision receiving traffic, request logs, container startup/listening port, service account, secrets/configuration, concurrency and backend limits. A healthy previous revision offers a rollback option only if data/schema compatibility remains intact.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Request-driven stateless container | Cloud Run service. |
| Finite batch container | Cloud Run Job. |
| Process object-created events | Eventarc/function or Cloud Run handler with idempotent processing. |
Traps
- Deploying a new revision and shifting traffic are separate operations.
- Event-driven does not mean duplicate-free business execution.
Active recall
1. Runtime identity versus invoker identity?
Runtime identity authorizes the code’s API calls; invoker identity authorizes requests to the service.
2. Why set maximum instances?
To bound scaling/cost or protect dependencies, while planning for rejected/queued load.
3. Why use an idempotency key?
To prevent repeated delivery from repeating a business effect.
4. Does VPC egress make ingress private?
No. Ingress access is a separate setting/path.
5. Why can rollback fail after a database migration?
The old revision may be incompatible with changed data or schema.