Pub/Sub
Pub/Sub is Google Cloud's managed messaging service: publishers send messages to a topic and every subscription receives them. The GCP platform uses it in two places, the security alerts topic of the GCP Enterprise Baseline and the event delivery behind the Data and ETL Blueprint's trigger.
What it does
A topic receives messages from publishers. Each subscription on the topic gets its own copy of every message: a pull subscription waits for a consumer to fetch messages, a push subscription delivers each one to an HTTPS endpoint, optionally with an OIDC token that proves who sent it. A message the consumer does not acknowledge is redelivered under the subscription's retry policy, and a topic can retain messages for a period so that a stopped consumer can catch up. Other Google services, such as Security Command Center and Eventarc, publish to topics on your behalf through their service agents.
How BuiltForProd uses it
The security alerts topic. The metrics-scope unit creates acme-security-alerts in acme-core-security, with a seven-day message retention and Google-managed encryption, since findings carry no secrets.
The organization notification config acme-high-critical of Security Command Center publishes every active, unmuted HIGH or CRITICAL finding to it. The topic is part of the landing-zone contract: pm-publish writes its name to every stage project as platform--alerts-topic. With the optional notifier on, the scc unit adds the push subscription acme-scc-notifier, which delivers each message to the notifier's Cloud Run service with an OIDC token of the notifier's own account (the only principal allowed to invoke it), retries with a backoff of 10 to 600 seconds and never expires. Email delivery of the same findings goes through the scc-high-findings alert of Cloud Monitoring, not through Pub/Sub.
ETL event delivery. The Data and ETL Blueprint starts processing when a file lands in its raw bucket. Eventarc carries the Cloud Storage object.finalized event over Pub/Sub to the trigger service, so the blueprint's data-lake unit grants the project's Cloud Storage service agent roles/pubsub.publisher; without it Eventarc delivers nothing. Delivery authenticates as the trigger's own Eventarc identity, which may invoke only that service.
The Pub/Sub API is in the project baseline's API list, so every project can use it without a manual step.
Terms you will see
| Term | Meaning |
|---|---|
| Topic | The named channel publishers send to: acme-security-alerts. |
| Push subscription | A subscription that delivers each message to an HTTPS endpoint. |
| OIDC token | The signed identity a push delivery carries, checked by the receiver. |
| Message retention | How long the topic keeps messages: seven days here. |
platform--alerts-topic | The contract parameter that names the alerts topic in each stage. |
Where to read more
- GCP Enterprise Baseline overview and the GCP Data and ETL Blueprint overview.
- Security Command Center for the findings the topic carries.
- Cloud Monitoring for the email alerts.