Skip to main content

Parameter Manager

Parameter Manager stores non-secret configuration as versioned parameters. The GCP Enterprise Baseline publishes its landing-zone contract there, 24 parameters in each stage project, and the blueprints read the contract and record their own outputs and deployed image tags beside it.

What it does​

A parameter is a named configuration value in a project with one or more versions. Its format is UNFORMATTED, YAML or JSON; a JSON or YAML parameter is validated when a version is written. Readers need roles/parametermanager.parameterViewer. Unlike Secret Manager, Parameter Manager is for values that are not secret but must be shared between systems that do not share state, such as a subnet name or the image tag a service runs.

How BuiltForProd uses it​

The contract. The pm-publish unit runs in every stage project from the plat-project template and writes each value as <service>--<key>, with a single version v1 whose data is updated in place. Values that are JSON objects are stored as JSON, everything else as UNFORMATTED:

GCP/acme-gcp-platform-baseline/units/pm-publish/terragrunt.hcl (lines 175-215)
inputs = {
parameters = merge(
{
# Network: the stage's domain VPC and its subnets in this region. The proxy-only subnet is the domain's
# one in this region (one per VPC and region), owned by one stage and shared by all of them.
"vpc--network" = dependency.vpc.outputs.network_name
"vpc--network-self-link" = dependency.vpc.outputs.network_self_link
"vpc--domain" = local.domain
"vpc--host-project" = include.root.locals.prj.host
"vpc--subnet--nodes" = dependency.vpc.outputs.subnets["${local.region}:${local.key}:nodes"].self_link
"vpc--subnet--data" = dependency.vpc.outputs.subnets["${local.region}:${local.key}:data"].self_link
"vpc--subnet--proxy" = dependency.vpc.outputs.proxy_subnets[local.region].self_link
"vpc--subnet--psc" = dependency.vpc.outputs.subnets["${local.region}:${local.key}:psc"].self_link
"vpc--subnet--nodes--pods-range" = "pods" # secondary range names fixed by network_map.yaml
"vpc--subnet--nodes--services-range" = "services" # idem
"vpc--cidr" = dependency.ipam.outputs.subnets_by_region[local.region][local.key].primary_cidr
"vpc--master-range" = dependency.ipam.outputs.gke_master_ranges[local.region][local.key]

# DNS: the stage's public zone (core-dns) and the private zone (core-network).
"dns--public-zone" = dependency.dns_zones.outputs.zone_names[local.stage]
"dns--public-zone-project" = dependency.dns_zones.outputs.project_id
"dns--private-zone" = dependency.private_dns.outputs.zone_name
"dns--private-zone-project" = dependency.private_dns.outputs.project_id

# Identity of the project.
"project--id" = include.root.locals.target_project_id
"project--number" = dependency.baseline.outputs.project_number

# Cloud Armor rule template rendered by the blueprints' security policies (JSON).
"waf--policy-template" = file("${get_repo_root()}/policies/cloud-armor-template.json")
},
# Platform services (core projects; feature platform_services, see the header). The registry path has
# no trailing slash: images are <platform--artifact-registry>/<repository>/<image>:<tag>.
feature.platform_services.value ? {
"platform--artifact-registry" = dependency.artifact_registry.outputs.registry_path
"platform--notification-channel" = length(dependency.metrics_scope.outputs.notification_channel_ids) > 0 ? dependency.metrics_scope.outputs.notification_channel_ids[0] : "none"
"platform--alerts-topic" = dependency.metrics_scope.outputs.alerts_topic_id
"platform--kms-sops-key" = dependency.kms_sops.outputs.key_ids["sops-${local.stage}"]
"platform--secrets-syncer-sa" = dependency.secrets_syncer.outputs.email
} : {},
)
GroupParametersWhat they hold
vpc--*12The stage's isolation-domain VPC, its three subnets and the domain's proxy-only subnet, the GKE secondary range names, CIDR and control-plane range
dns--*4The stage's public zone in acme-core-dns and the private zone in acme-core-network
project--*2The project ID and number
waf--policy-template1The Google Cloud Armor rule template (JSON)
platform--*5The Artifact Registry path, the notification channel (or none), the alerts topic, the stage's SOPS key and the secrets syncer account

The 19 base parameters come from the network, DNS and identity units. The five platform-services parameters sit behind the unit's platform_services feature flag, on by default. Readers are the CI accounts of the four blueprint repositories and the stage's engineer groups, with Parameter Viewer on the project: every parameter of a stage project is contract or blueprint output, never a secret, which stays in Secret Manager.

Reading the contract. Every blueprint module that needs a landing-zone value reads it through the same contract.tf, one data source per parameter its unit lists, so the blueprints never look up or hard-code a VPC, zone or project. The Web App Blueprint's guard script check-contract.py fails a pull request that names a parameter the landing zone does not publish, before a plan would.

What the blueprints write. The Web App Blueprint publishes the names its chart and its code pipeline need, such as api--gateway-address, api--certificate-map, api--security-policy, frontend--service and frontend--url-map. Two parameters record the image a Cloud Run service runs, because Artifact Registry tags are immutable and the service cannot follow a moving tag:

ParameterCreated withWritten by
frontend--image-tagbootstrap (a placeholder image runs)the web app code pipeline
etl-trigger--image-tagthe stage's initial_image_tagthe ETL code pipeline

The infrastructure code creates each one once and ignores later changes to its value, then reads it back, so a plan always sees the image that is actually running and never rolls a deployment back.

Terms you will see​

TermMeaning
ParameterA named, versioned configuration value in a project.
v1The single version of every contract parameter, updated in place.
<service>--<key>The naming pattern, such as vpc--subnet--nodes or dns--public-zone.
platform_servicesThe pm-publish feature flag behind the five platform--* parameters.
contract.tfThe one reader file every blueprint module that uses the contract carries.

Where to read more​