At a high level, a Build describes where to find source code, how to build it (for example, the builder image to run on the source), and where to store the built artifacts.
Fields can include the following variables, which will be expanded when the build is created:
$PROJECT_ID: the project ID of the build.
$PROJECT_NUMBER: the project number of the build.
$LOCATION: the location/region of the build.
$BUILD_ID: the autogenerated ID of the build.
$REPO_NAME: the source repository name specified by RepoSource.
$BRANCH_NAME: the branch name specified by RepoSource.
$TAG_NAME: the tag name specified by RepoSource.
REVISIONIDorREVISION_ID or REVISIONIDorCOMMIT_SHA: the commit SHA specified by RepoSource or resolved from the specified branch or tag.
SHORTSHA:first7charactersofSHORT_SHA: first 7 characters of SHORTSHA:first7charactersofREVISION_ID or $COMMIT_SHA.
string Output only. The 'Build' name with format: projects/{project}/locations/{location}/builds/{build}, where {build} is a unique identifier generated by the service.
id
string Output only. Unique identifier of the build.
string Output only. Customer-readable message about the current status.
source
object (Source) Optional. The location of the source files to build.
steps[]
object (BuildStep) Required. The operations to be performed on the workspace.
results
object (Results) Output only. Results of the build.
createTime
string (Timestamp format) Output only. Time at which the request to create the build was received.A timestamp in RFC3339 UTC "Zulu" format, with nanosecond resolution and up to nine fractional digits. Examples: "2014-10-02T15:01:23Z" and "2014-10-02T15:01:23.045123456Z".
startTime
string (Timestamp format) Output only. Time at which execution of the build was started.A timestamp in RFC3339 UTC "Zulu" format, with nanosecond resolution and up to nine fractional digits. Examples: "2014-10-02T15:01:23Z" and "2014-10-02T15:01:23.045123456Z".
finishTime
string (Timestamp format) Output only. Time at which execution of the build was finished.The difference between finishTime and startTime is the duration of the build's execution.A timestamp in RFC3339 UTC "Zulu" format, with nanosecond resolution and up to nine fractional digits. Examples: "2014-10-02T15:01:23Z" and "2014-10-02T15:01:23.045123456Z".
timeout
string (Duration format) Amount of time that this build should be allowed to run, to second granularity. If this amount of time elapses, work on the build will cease and the build status will be TIMEOUT.timeout starts ticking from startTime.Default time is 60 minutes.A duration in seconds with up to nine fractional digits, ending with 's'. Example: "3.5s".
images[]
string A list of images to be pushed upon the successful completion of all build steps.The images are pushed using the builder service account's credentials.The digests of the pushed images will be stored in the Build resource's results field.If any of the images fail to be pushed, the build status is marked FAILURE.
queueTtl
string (Duration format) TTL in queue for this build. If provided and the build is enqueued longer than this value, the build will expire and the build status will be EXPIRED.The TTL starts ticking from createTime.A duration in seconds with up to nine fractional digits, ending with 's'. Example: "3.5s".
artifacts
object (Artifacts) Artifacts produced by the build that should be uploaded upon successful completion of all build steps.
logsBucket
string Cloud Storage bucket where logs should be written (see Bucket Name Requirements). Logs file names will be of the format logsBucket/log−{logsBucket}/log-logsBucket/log−{build_id}.txt.
sourceProvenance
object (SourceProvenance) Output only. A permanent fixed identifier for source.
buildTriggerId
string Output only. The ID of the BuildTrigger that triggered this build, if it was triggered automatically.
options
object (BuildOptions) Special options for this build.
logUrl
string Output only. URL to logs for this build in Google Cloud Console.
substitutions
map (key: string, value: string) Substitutions data for Build resource.An object containing a list of "key": value pairs. Example: { "name": "wrench", "mass": "1.3kg", "count": "3" }.
tags[]
string Tags for annotation of a Build. These are not docker tags.
secrets[]
object (Secret) Secrets to decrypt using Cloud Key Management Service. Note: Secret Manager is the recommended technique for managing sensitive data with Cloud Build. Use availableSecrets to configure builds to access secrets from Secret Manager. For instructions, see: https://cloud.google.com/cloud-build/docs/securing-builds/use-secrets
timing
map (key: string, value: object (TimeSpan)) Output only. Stores timing information for phases of the build. Valid keys are: BUILD: time to execute all build steps. PUSH: time to push all artifacts including docker images and non docker artifacts. FETCHSOURCE: time to fetch source. SETUPBUILD: time to set up build. If the build does not specify source or images, these keys will not be included.An object containing a list of "key": value pairs. Example: { "name": "wrench", "mass": "1.3kg", "count": "3" }.
approval
object (BuildApproval) Output only. Describes this build's approval configuration, status, and result.
serviceAccount
string IAM service account whose credentials will be used at build runtime. Must be of the format projects/{PROJECT_ID}/serviceAccounts/{ACCOUNT}. ACCOUNT can be email address or uniqueId of the service account.
availableSecrets
object (Secrets) Secrets and secret environment variables.
warnings[]
object (Warning) Output only. Non-fatal problems encountered during the execution of the build.
gitConfig
object (GitConfig) Optional. Configuration for git operations.
failureInfo
object (FailureInfo) Output only. Contains information about the build when status=FAILURE.
Status
Possible status of a build or build step.
Enums
STATUS_UNKNOWN
Status of the build is unknown.
PENDING
Build has been created and is pending execution and queuing. It has not been queued.
QUEUED
Build or step is queued; work has not yet begun.
WORKING
Build or step is being executed.
SUCCESS
Build or step finished successfully.
FAILURE
Build or step failed to complete successfully.
INTERNAL_ERROR
Build or step failed due to an internal cause.
TIMEOUT
Build or step took longer than was allowed.
CANCELLED
Build or step was canceled by a user.
EXPIRED
Build was enqueued for longer than the value of queueTtl.
Source
Location of the source in a supported storage service.
JSON representation
{ // Union field source can be only one of the following: "storageSource": { object (StorageSource) }, "repoSource": { object (RepoSource) }, "gitSource": { object (GitSource) }, "storageSourceManifest": { object (StorageSourceManifest) }, "connectedRepository": { object (ConnectedRepository) }, "developerConnectConfig": { object (DeveloperConnectConfig) } // End of list of possible types for union field source. }
Fields
Union field source. Location of source. source can be only one of the following:
storageSource
object (StorageSource) If provided, get the source from this location in Cloud Storage.
repoSource
object (RepoSource) If provided, get the source from this location in a Cloud Source Repository.
gitSource
object (GitSource) If provided, get the source from this Git repository.
storageSourceManifest
object (StorageSourceManifest) If provided, get the source from this manifest in Cloud Storage. This feature is in Preview; see description here.
connectedRepository
object (ConnectedRepository) Optional. If provided, get the source from this 2nd-gen Google Cloud Build repository resource.
developerConnectConfig
object (DeveloperConnectConfig) If provided, get the source from this Developer Connect config.
StorageSource
Location of the source in an archive file in Cloud Storage.
string Required. Cloud Storage object containing the source.This object must be a zipped (.zip) or gzipped archive file (.tar.gz) containing source to build.
generation
string (int64 format) Optional. Cloud Storage generation for the object. If the generation is omitted, the latest generation will be used.
sourceFetcher
enum (SourceFetcher) Optional. Option to specify the tool to fetch the source file for the build.
SourceFetcher
Specifies the tool to fetch the source file for the build.
Enums
SOURCE_FETCHER_UNSPECIFIED
Unspecified defaults to GSUTIL.
GSUTIL
Use the "gsutil" tool to download the source file.
GCS_FETCHER
Use the Cloud Storage Fetcher tool to download the source file.
GitSource
Location of the source in any accessible Git repository.
string Optional. Directory, relative to the source root, in which to run the build.This must be a relative path. If a step's dir is specified and is an absolute path, this value is ignored for that step's execution.
revision
string Optional. The revision to fetch from the Git repository such as a branch, a tag, a commit SHA, or any Git ref.Cloud Build uses git fetch to fetch the revision from the Git repository; therefore make sure that the string you provide for revision is parsable by the command. For information on string values accepted by git fetch, see https://git-scm.com/docs/gitrevisions#_specifying_revisions. For information on git fetch, see https://git-scm.com/docs/git-fetch.
StorageSourceManifest
Location of the source manifest in Cloud Storage. This feature is in Preview; see description here.
string Required. The name of the container image that will run this particular build step.If the image is available in the host's Docker daemon's cache, it will be run directly. If not, the host will attempt to pull the image first, using the builder service account's credentials if necessary.The Docker daemon's cache will already have the latest versions of all of the officially supported build steps (https://github.com/GoogleCloudPlatform/cloud-builders). The Docker daemon will also have cached many of the layers for some popular images, like "ubuntu", "debian", but they will be refreshed at the time you attempt to use them.If you built an image in a previous build step, it will be stored in the host's Docker daemon's cache and is available to use as the name for a later build step.
env[]
string A list of environment variable definitions to be used when running a step.The elements are of the form "KEY=VALUE" for the environment variable "KEY" being given the value "VALUE".
args[]
string A list of arguments that will be presented to the step when it is started.If the image used to run the step's container has an entrypoint, the args are used as arguments to that entrypoint. If the image does not define an entrypoint, the first element in args is used as the entrypoint, and the remainder will be used as arguments.
dir
string Working directory to use when running this step's container.If this value is a relative path, it is relative to the build's working directory. If this value is absolute, it may be outside the build's working directory, in which case the contents of the path may not be persisted across build step executions, unless a volume for that path is specified.If the build specifies a RepoSource with dir and a step with a dir, which specifies an absolute path, the RepoSource dir is ignored for the step's execution.
id
string Unique identifier for this build step, used in waitFor to reference this build step as a dependency.
waitFor[]
string The ID(s) of the step(s) that this build step depends on. This build step will not start until all the build steps in waitFor have completed successfully. If waitFor is empty, this build step will start when all previous build steps in the Build.Steps list have completed successfully.
entrypoint
string Entrypoint to be used instead of the build step image's default entrypoint. If unset, the image's default entrypoint is used.
secretEnv[]
string A list of environment variables which are encrypted using a Cloud Key Management Service crypto key. These values must be specified in the build's Secret.
volumes[]
object (Volume) List of volumes to mount into the build step.Each volume is created as an empty volume prior to execution of the build step. Upon completion of the build, volumes and their contents are discarded.Using a named volume in only one step is not valid as it is indicative of a build request with an incorrect configuration.
timing
object (TimeSpan) Output only. Stores timing information for executing this build step.
pullTiming
object (TimeSpan) Output only. Stores timing information for pulling this build step's builder image only.
timeout
string (Duration format) Time limit for executing this build step. If not defined, the step has no time limit and will be allowed to continue to run until either it completes or the build itself times out.A duration in seconds with up to nine fractional digits, ending with 's'. Example: "3.5s".
status
enum (Status) Output only. Status of the build step. At this time, build step status is only updated on build completion; step status is not updated in real-time as the build progresses.
allowFailure
boolean Allow this build step to fail without failing the entire build.If false, the entire build will fail if this step fails. Otherwise, the build will succeed, but this step will still have a failure status. Error information will be reported in the failure_detail field.
exitCode
integer Output only. Return code from running the step.
allowExitCodes[]
integer Allow this build step to fail without failing the entire build if and only if the exit code is one of the specified codes. If allowFailure is also specified, this field will take precedence.
script
string A shell script to be executed in the step.When script is provided, the user cannot specify the entrypoint or args.
automapSubstitutions
boolean Option to include built-in and custom substitutions as env variables for this build step. This option will override the global option in BuildOption.
Volume
Volume describes a Docker container volume which is mounted into build steps in order to persist files across build step execution.
JSON representation
{ "name": string, "path": string }
Fields
name
string Name of the volume to mount.Volume names must be unique per build step and must be valid names for Docker volumes. Each named volume must be used by at least two build steps.
path
string Path at which to mount the volume.Paths must be absolute and cannot conflict with other volume paths on the same build step or with certain reserved volume paths.
TimeSpan
Start and end times for a build execution phase.
JSON representation
{ "startTime": string, "endTime": string }
Fields
startTime
string (Timestamp format) Start of time span.A timestamp in RFC3339 UTC "Zulu" format, with nanosecond resolution and up to nine fractional digits. Examples: "2014-10-02T15:01:23Z" and "2014-10-02T15:01:23.045123456Z".
endTime
string (Timestamp format) End of time span.A timestamp in RFC3339 UTC "Zulu" format, with nanosecond resolution and up to nine fractional digits. Examples: "2014-10-02T15:01:23Z" and "2014-10-02T15:01:23.045123456Z".
object (BuiltImage) Container images that were built as a part of the build.
buildStepImages[]
string List of build step digests, in the order corresponding to build step indices.
artifactManifest
string Path to the artifact manifest for non-container artifacts uploaded to Cloud Storage. Only populated when artifacts are uploaded to Cloud Storage.
numArtifacts
string (int64 format) Number of non-container artifacts uploaded to Cloud Storage. Only populated when artifacts are uploaded to Cloud Storage.
buildStepOutputs[]
string (bytes format) List of build step outputs, produced by builder images, in the order corresponding to build step indices.Cloud Builders can produce this output by writing to BUILDEROUTPUT/output.Onlythefirst50KBofdataisstored.NotethattheBUILDER_OUTPUT/output. Only the first 50KB of data is stored. Note that the BUILDEROUTPUT/output.Onlythefirst50KBofdataisstored.NotethattheBUILDER_OUTPUT variable is read-only and can't be substituted.A base64-encoded string.
artifactTiming
object (TimeSpan) Time to push all non-container artifacts to Cloud Storage.
pythonPackages[]
object (UploadedPythonPackage) Python artifacts uploaded to Artifact Registry at the end of the build.
mavenArtifacts[]
object (UploadedMavenArtifact) Maven artifacts uploaded to Artifact Registry at the end of the build.
npmPackages[]
object (UploadedNpmPackage) Npm packages uploaded to Artifact Registry at the end of the build.
string A list of images to be pushed upon the successful completion of all build steps.The images will be pushed using the builder service account's credentials.The digests of the pushed images will be stored in the Build resource's results field.If any of the images fail to be pushed, the build is marked FAILURE.
objects
object (ArtifactObjects) A list of objects to be uploaded to Cloud Storage upon successful completion of all build steps.Files in the workspace matching specified paths globs will be uploaded to the specified Cloud Storage location using the builder service account's credentials.The location and generation of the uploaded objects will be stored in the Build resource's results field.If any objects fail to be pushed, the build is marked FAILURE.
mavenArtifacts[]
object (MavenArtifact) A list of Maven artifacts to be uploaded to Artifact Registry upon successful completion of all build steps.Artifacts in the workspace matching specified paths globs will be uploaded to the specified Artifact Registry repository using the builder service account's credentials.If any artifacts fail to be pushed, the build is marked FAILURE.
pythonPackages[]
object (PythonPackage) A list of Python packages to be uploaded to Artifact Registry upon successful completion of all build steps.The build service account credentials will be used to perform the upload.If any objects fail to be pushed, the build is marked FAILURE.
npmPackages[]
object (NpmPackage) A list of npm packages to be uploaded to Artifact Registry upon successful completion of all build steps.Npm packages in the specified paths will be uploaded to the specified Artifact Registry repository using the builder service account's credentials.If any packages fail to be pushed, the build is marked FAILURE.
ArtifactObjects
Files in the workspace to upload to Cloud Storage upon successful completion of all build steps.
string Cloud Storage bucket and optional object path, in the form "gs://bucket/path/to/somewhere/". (see Bucket Name Requirements).Files in the workspace matching any path pattern will be uploaded to Cloud Storage with this location as a prefix.
paths[]
string Path globs used to match files in the build's workspace.
timing
object (TimeSpan) Output only. Stores timing information for pushing all artifact objects.
MavenArtifact
A Maven artifact to upload to Artifact Registry upon successful completion of all build steps.
string Artifact Registry repository, in the form "https://$REGION-maven.pkg.dev/$PROJECT/$REPOSITORY"Artifact in the workspace specified by path will be uploaded to Artifact Registry with this location as a prefix.
path
string Path to an artifact in the build's workspace to be uploaded to Artifact Registry. This can be either an absolute path, e.g. /workspace/my-app/target/my-app-1.0.SNAPSHOT.jar or a relative path from /workspace, e.g. my-app/target/my-app-1.0.SNAPSHOT.jar.
artifactId
string Maven artifactId value used when uploading the artifact to Artifact Registry.
groupId
string Maven groupId value used when uploading the artifact to Artifact Registry.
version
string Maven version value used when uploading the artifact to Artifact Registry.
PythonPackage
Python package to upload to Artifact Registry upon successful completion of all build steps. A package can encapsulate multiple objects to be uploaded to a single repository.
JSON representation
{ "repository": string, "paths": [ string ] }
Fields
repository
string Artifact Registry repository, in the form "https://$REGION-python.pkg.dev/$PROJECT/$REPOSITORY"Files in the workspace matching any path pattern will be uploaded to Artifact Registry with this location as a prefix.
paths[]
string Path globs used to match files in the build's workspace. For Python/ Twine, this is usually dist/*, and sometimes additionally an .asc file.
NpmPackage
Npm package to upload to Artifact Registry upon successful completion of all build steps.
JSON representation
{ "repository": string, "packagePath": string }
Fields
repository
string Artifact Registry repository, in the form "https://$REGION-npm.pkg.dev/$PROJECT/$REPOSITORY"Npm package in the workspace specified by path will be zipped and uploaded to Artifact Registry with this location as a prefix.
packagePath
string Path to the package.json. e.g. workspace/path/to/package
SourceProvenance
Provenance of the source. Ways to find the original source, or verify that some source was used for this build.
object (StorageSource) A copy of the build's source.storage_source, if exists, with any generations resolved.
resolvedRepoSource
object (RepoSource) A copy of the build's source.repo_source, if exists, with any revisions resolved.
resolvedStorageSourceManifest
object (StorageSourceManifest) A copy of the build's source.storage_source_manifest, if exists, with any revisions resolved. This feature is in Preview.
resolvedConnectedRepository
object (ConnectedRepository) Output only. A copy of the build's source.connected_repository, if exists, with any revisions resolved.
resolvedGitSource
object (GitSource) Output only. A copy of the build's source.git_source, if exists, with any revisions resolved.
fileHashes
map (key: string, value: object (FileHashes)) Output only. Hash(es) of the build source, which can be used to verify that the original source integrity was maintained in the build. Note that FileHashes will only be populated if BuildOptions has requested a SourceProvenanceHash.The keys to this map are file paths used as build source and the values contain the hash values for those files.If the build source came in a single package such as a gzipped tarfile (.tar.gz), the FileHash will be for the single path to that file.An object containing a list of "key": value pairs. Example: { "name": "wrench", "mass": "1.3kg", "count": "3" }.
BuildOptions
Optional arguments to enable specific features of builds.
enum (MachineType) Compute Engine machine type on which to run the build.
diskSizeGb
string (int64 format) Requested disk size for the VM that runs the build. Note that this is NOT "disk free"; some of the space will be used by the operating system and build utilities. Also note that this is the minimum disk size that will be allocated for the build -- the build may run with a larger disk than requested. At present, the maximum disk size is 4000GB; builds that request more than the maximum are rejected with an error.
substitutionOption
enum (SubstitutionOption) Option to specify behavior when there is an error in the substitution checks.NOTE: this is always set to ALLOW_LOOSE for triggered builds and cannot be overridden in the build configuration file.
dynamicSubstitutions
boolean Option to specify whether or not to apply bash style string operations to the substitutions.NOTE: this is always enabled for triggered builds and cannot be overridden in the build configuration file.
automapSubstitutions
boolean Option to include built-in and custom substitutions as env variables for all build steps.
logStreamingOption
enum (LogStreamingOption) Option to define build log streaming behavior to Cloud Storage.
workerPool**(deprecated)**
string This field deprecated; please use pool.name instead.
enum (LoggingMode) Option to specify the logging mode, which determines if and where build logs are stored.
env[]
string A list of global environment variable definitions that will exist for all build steps in this build. If a variable is defined in both globally and in a build step, the variable will use the build step value.The elements are of the form "KEY=VALUE" for the environment variable "KEY" being given the value "VALUE".
secretEnv[]
string A list of global environment variables, which are encrypted using a Cloud Key Management Service crypto key. These values must be specified in the build's Secret. These variables will be available to all build steps in this build.
volumes[]
object (Volume) Global list of volumes to mount for ALL build stepsEach volume is created as an empty volume prior to starting the build process. Upon completion of the build, volumes and their contents are discarded. Global volume names and paths cannot conflict with the volumes defined a build step.Using a global volume in a build with only one step is not valid as it is indicative of a build request with an incorrect configuration.
string The WorkerPool resource to execute the build on. You must have cloudbuild.workerpools.use on the project hosting the WorkerPool.Format projects/{project}/locations/{location}/workerPools/{workerPoolId}
LoggingMode
Specifies the logging mode.
Enums
LOGGING_UNSPECIFIED
The service determines the logging mode. The default is LEGACY. Do not rely on the default logging behavior as it may change in the future.
LEGACY
Build logs are stored in Cloud Logging and Cloud Storage.
GCS_ONLY
Build logs are stored in Cloud Storage.
STACKDRIVER_ONLY
This option is the same as CLOUD_LOGGING_ONLY.
CLOUD_LOGGING_ONLY
Build logs are stored in Cloud Logging. Selecting this option will not allow logs streaming.
NONE
Turn off all logging. No build logs will be captured.
Bucket is located in user-owned project in the same region as the build. The builder service account must have access to create and write to Cloud Storage buckets in the build project.
LEGACY_BUCKET
Bucket is located in a Google-owned project and is not regionalized.
string Cloud KMS key name to use to decrypt these envs.
secretEnv
map (key: string, value: string (bytes format)) Map of environment variable name to its encrypted value.Secret environment variables must be unique across all of a build's secrets, and must be used by at least one build step. Values can be at most 64 KB in size. There can be at most 100 secret values across all of a build's secrets.An object containing a list of "key": value pairs. Example: { "name": "wrench", "mass": "1.3kg", "count": "3" }.
BuildApproval
BuildApproval describes a build's approval configuration, state, and result.
string Output only. Email of the user that called the builds.approve API to approve or reject a build at the time that the API was called.
approvalTime
string (Timestamp format) Output only. The time when the approval decision was made.A timestamp in RFC3339 UTC "Zulu" format, with nanosecond resolution and up to nine fractional digits. Examples: "2014-10-02T15:01:23Z" and "2014-10-02T15:01:23.045123456Z".
decision
enum (Decision) Required. The decision of this manual approval.
comment
string Optional. An optional comment for this manual approval result.
url
string Optional. An optional URL tied to this manual approval result. This field is essentially the same as comment, except that it will be rendered by the UI differently. An example use case is a link to an external job that approved this Build.
Decision
Specifies whether or not this manual approval result is to approve or reject a build.
object (SecretManagerSecret) Secrets in Secret Manager and associated secret environment variable.
inline[]
object (InlineSecret) Secrets encrypted with KMS key and the associated secret environment variable.
SecretManagerSecret
Pairs a secret environment variable with a SecretVersion in Secret Manager.
JSON representation
{ "versionName": string, "env": string }
Fields
versionName
string Resource name of the SecretVersion. In format: projects/*/secrets/*/versions/*
env
string Environment variable name to associate with the secret. Secret environment variables must be unique across all of a build's secrets, and must be used by at least one build step.
InlineSecret
Pairs a set of secret environment variables mapped to encrypted values with the Cloud KMS key to use to decrypt the value.
string Resource name of Cloud KMS crypto key to decrypt the encrypted value. In format: projects/*/locations/*/keyRings/*/cryptoKeys/*
envMap
map (key: string, value: string (bytes format)) Map of environment variable name to its encrypted value.Secret environment variables must be unique across all of a build's secrets, and must be used by at least one build step. Values can be at most 64 KB in size. There can be at most 100 secret values across all of a build's secrets.An object containing a list of "key": value pairs. Example: { "name": "wrench", "mass": "1.3kg", "count": "3" }.
Warning
A non-fatal problem encountered during the execution of the build.
object (HttpConfig) Configuration for HTTP related git operations.
HttpConfig
HttpConfig is a configuration for HTTP related git operations.
JSON representation
{ "proxySecretVersionName": string }
Fields
proxySecretVersionName
string SecretVersion resource of the HTTP proxy URL. The Service Account used in the build (either the default Service Account or user-specified Service Account) should have secretmanager.versions.access permissions on this secret. The proxy URL should be in format [protocol://][user[:password]@]proxyhost[:port].
FailureInfo
A fatal problem encountered during the execution of the build.