Parameter Manager
Parameter Manager stores non-secret configuration as versioned parameters. The GCP Enterprise Baseline publishes its landing-zone contract there, 24 parameters in each stage project, and the blueprints read the contract and record their own outputs and deployed image tags beside it.
What it does
A parameter is a named configuration value in a project with one or more versions. Its format is UNFORMATTED, YAML or JSON; a JSON or YAML parameter is validated when a version is written. Readers need roles/parametermanager.parameterViewer. Unlike Secret Manager, Parameter Manager is for values that are not secret but must be shared between systems that do not share state, such as a subnet name or the image tag a service runs.
How BuiltForProd uses it
The contract. The pm-publish unit runs in every stage project from the plat-project template and writes each value as <service>--<key>, with a single version v1 whose data is updated in place. Values that are JSON objects are stored as JSON, everything else as UNFORMATTED:
inputs = {
parameters = merge(
{
# Network: the stage's domain VPC and its subnets in this region. The proxy-only subnet is the domain's
# one in this region (one per VPC and region), owned by one stage and shared by all of them.
"vpc--network" = dependency.vpc.outputs.network_name
"vpc--network-self-link" = dependency.vpc.outputs.network_self_link
"vpc--domain" = local.domain
"vpc--host-project" = include.root.locals.prj.host
"vpc--subnet--nodes" = dependency.vpc.outputs.subnets["${local.region}:${local.key}:nodes"].self_link
"vpc--subnet--data" = dependency.vpc.outputs.subnets["${local.region}:${local.key}:data"].self_link
"vpc--subnet--proxy" = dependency.vpc.outputs.proxy_subnets[local.region].self_link
"vpc--subnet--psc" = dependency.vpc.outputs.subnets["${local.region}:${local.key}:psc"].self_link
"vpc--subnet--nodes--pods-range" = "pods" # secondary range names fixed by network_map.yaml
"vpc--subnet--nodes--services-range" = "services" # idem
"vpc--cidr" = dependency.ipam.outputs.subnets_by_region[local.region][local.key].primary_cidr
"vpc--master-range" = dependency.ipam.outputs.gke_master_ranges[local.region][local.key]
# DNS: the stage's public zone (core-dns) and the private zone (core-network).
"dns--public-zone" = dependency.dns_zones.outputs.zone_names[local.stage]
"dns--public-zone-project" = dependency.dns_zones.outputs.project_id
"dns--private-zone" = dependency.private_dns.outputs.zone_name
"dns--private-zone-project" = dependency.private_dns.outputs.project_id
# Identity of the project.
"project--id" = include.root.locals.target_project_id
"project--number" = dependency.baseline.outputs.project_number
# Cloud Armor rule template rendered by the blueprints' security policies (JSON).
"waf--policy-template" = file("${get_repo_root()}/policies/cloud-armor-template.json")
},
# Platform services (core projects; feature platform_services, see the header). The registry path has
# no trailing slash: images are <platform--artifact-registry>/<repository>/<image>:<tag>.
feature.platform_services.value ? {
"platform--artifact-registry" = dependency.artifact_registry.outputs.registry_path
"platform--notification-channel" = length(dependency.metrics_scope.outputs.notification_channel_ids) > 0 ? dependency.metrics_scope.outputs.notification_channel_ids[0] : "none"
"platform--alerts-topic" = dependency.metrics_scope.outputs.alerts_topic_id
"platform--kms-sops-key" = dependency.kms_sops.outputs.key_ids["sops-${local.stage}"]
"platform--secrets-syncer-sa" = dependency.secrets_syncer.outputs.email
} : {},
)
| Group | Parameters | What they hold |
|---|---|---|
vpc--* | 12 | The stage's isolation-domain VPC, its three subnets and the domain's proxy-only subnet, the GKE secondary range names, CIDR and control-plane range |
dns--* | 4 | The stage's public zone in acme-core-dns and the private zone in acme-core-network |
project--* | 2 | The project ID and number |
waf--policy-template | 1 | The Google Cloud Armor rule template (JSON) |
platform--* | 5 | The Artifact Registry path, the notification channel (or none), the alerts topic, the stage's SOPS key and the secrets syncer account |
The 19 base parameters come from the network, DNS and identity units. The five platform-services parameters sit behind the unit's platform_services feature flag, on by default. Readers are the CI accounts of the four blueprint repositories and the stage's engineer groups, with Parameter Viewer on the project: every parameter of a stage project is contract or blueprint output, never a secret, which stays in Secret Manager.
Reading the contract. Every blueprint module that needs a landing-zone value reads it through the same contract.tf, one data source per parameter its unit lists, so the blueprints never look up or hard-code a VPC, zone or project. The Web App Blueprint's guard script check-contract.py fails a pull request that names a parameter the landing zone does not publish, before a plan would.
What the blueprints write. The Web App Blueprint publishes the names its chart and its code pipeline need, such as api--gateway-address, api--certificate-map, api--security-policy, frontend--service and frontend--url-map. Two parameters record the image a Cloud Run service runs, because Artifact Registry tags are immutable and the service cannot follow a moving tag:
| Parameter | Created with | Written by |
|---|---|---|
frontend--image-tag | bootstrap (a placeholder image runs) | the web app code pipeline |
etl-trigger--image-tag | the stage's initial_image_tag | the ETL code pipeline |
The infrastructure code creates each one once and ignores later changes to its value, then reads it back, so a plan always sees the image that is actually running and never rolls a deployment back.
Terms you will see
| Term | Meaning |
|---|---|
| Parameter | A named, versioned configuration value in a project. |
v1 | The single version of every contract parameter, updated in place. |
<service>--<key> | The naming pattern, such as vpc--subnet--nodes or dns--public-zone. |
platform_services | The pm-publish feature flag behind the five platform--* parameters. |
contract.tf | The one reader file every blueprint module that uses the contract carries. |
Where to read more
- GCP Enterprise Baseline overview and the GCP Web App Blueprint overview and GCP Data and ETL Blueprint overview.
- Secret Manager for the values that are secret.
- Landing zones for why the foundation publishes what workloads build on.