Skip to main content

GCP Integration with Orkes Conductor

To use AI tasks like List Files and Parse Document that need to access files or documents stored in Google Cloud Storage (GCS), you must integrate your Conductor cluster with GCP. This integration is required when accessing private buckets or resources that aren’t publicly available. This guide explains how to integrate GCP with Orkes Conductor. Here’s an overview:

  1. Get the required credentials from GCP.
  2. Configure a new GCP integration in Orkes Conductor.
  3. Set access limits for the integration to govern which applications or groups can use it.

Step 1: Get the GCP credentials

To integrate GCP with Orkes Conductor, retrieve the following credentials from the Google Cloud Console:

  • Project ID
  • Location
  • Service account JSON

Get the project ID

To get the project ID:

  1. Sign in to the Google Cloud Console.
  2. Create a new project or select an existing one.
  3. Get the Project ID from the dashboard.

Get project ID from Google Cloud Console

For more information, refer to the official documentation on creating and managing projects in GCP.

Get the location

The region where your Google Cloud project or storage bucket is hosted.

For more information, refer to the official documentation on Bucket location.

Get the service account JSON

To get the service account JSON:

  1. Go to IAM & Admin > Service Accounts from the left menu on your GCP console.
  2. Create a new service or select an existing one.
  3. In the Keys tab, select Add key > Create new key.

Get Service Account JSON from Google Cloud Console

  1. Select the key type as JSON.
  2. Select Create to download the JSON file.

Get Service Account JSON key from Google Cloud Console

To use GCP with Orkes Conductor, you must enable Cloud Storage from the GCP console.

Enable Cloud Storage API

To enable Cloud Storage API:

  1. Go to APIs & Services > Enabled APIs & services from the left menu on your GCP console.
  2. Select + Enable APIs and Services.

Enabling APIs and services from GCP console

  1. In the API Library, search for Cloud Storage API.

Enabling Cloud Storage API

  1. Select Enable.

Enabling Cloud Storage API

Once enabled, the Cloud Storage API is ready for use with your GCP project.

Step 2: Add an integration for GCP

After obtaining the credentials, add a GCP integration to your Conductor cluster.

To create a GCP integration:

  1. Go to Integrations from the left navigation menu on your Conductor cluster.
  2. Select + New integration.
  3. In the Cloud Credentials section, choose GCP.
  4. Select + Add and enter the following parameters:
ParemetersDescription
Integration nameA name for the integration.
Project IDThe Project ID retrieved from the GCP console.
LocationThe region where your GCP project is hosted. For example, us-central1.
Choose Service account credentials JSONUpload the service account JSON file (generated previously), which is a key file containing the credentials for authenticating the Orkes Conductor cluster with the GCP services.
DescriptionA description of the integration.

GCP Integration with Orkes Conductor

  1. (Optional) Toggle the Active button off if you don’t want to activate the integration instantly.
  2. Select Save.

Step 3: Set access limits to integration

Once the integration is configured, set access controls to manage which applications or groups can use the cloud provider.

To provide access to an application or group:

  1. Go to Access Control > Applications or Groups from the left navigation menu on your Conductor cluster.
  2. Create a new group/application or select an existing one.
  3. In the Permissions section, select + Add Permission.
  4. In the Integration tab, select the required integration and toggle the necessary permissions.

Configuring RBAC for GCP Integration

The group or application can now access the integration according to the configured permissions.

With the integration in place, you can now create workflows using the List Files task or the Parse Document task.