Quickstart: Deploy a Cloud Run function using the gcloud CLI
This page shows you how to deploy an HTTP Cloud Run function using the gcloud CLI.
Before you begin
- Sign in to your Google Cloud account. If you're new to Google Cloud, create an account to evaluate how our products perform in real-world scenarios. New customers also get $300 in free credits to run, test, and deploy workloads.
- 
      Install the Google Cloud CLI. 
- 
          If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity. 
- 
        To initialize the gcloud CLI, run the following command: gcloud init
- 
  
  
    Create or select a Google Cloud project. Roles required to select or create a project - Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
- 
      Create a project: To create a project, you need the Project Creator
      (roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
 - 
        Create a Google Cloud project: gcloud projects create PROJECT_ID Replace PROJECT_IDwith a name for the Google Cloud project you are creating.
- 
        Select the Google Cloud project that you created: gcloud config set project PROJECT_ID Replace PROJECT_IDwith your Google Cloud project name.
 
- 
  
    Verify that billing is enabled for your Google Cloud project. 
- 
  
  
    
      Enable the Artifact Registry, Cloud Build, Cloud Run Admin API, and Cloud Logging APIs: Roles required to enable APIs To enable APIs, you need the Service Usage Admin IAM role ( roles/serviceusage.serviceUsageAdmin), which contains theserviceusage.services.enablepermission. Learn how to grant roles.gcloud services enable artifactregistry.googleapis.com cloudbuild.googleapis.com run.googleapis.com logging.googleapis.com 
- 
    
        Grant roles to your user account. Run the following command once for each of the following IAM roles: roles/run.sourceDeveloper, roles/run.admin, roles/logging.viewergcloud projects add-iam-policy-binding PROJECT_ID --member="user:USER_IDENTIFIER" --role=ROLE Replace the following: - PROJECT_ID: Your project ID.
- USER_IDENTIFIER: The identifier for your user account. For example,- myemail@example.com.
- ROLE: The IAM role that you grant to your user account.
 
- 
      Install the Google Cloud CLI. 
- 
          If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity. 
- 
        To initialize the gcloud CLI, run the following command: gcloud init
- 
  
  
    Create or select a Google Cloud project. Roles required to select or create a project - Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
- 
      Create a project: To create a project, you need the Project Creator
      (roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
 - 
        Create a Google Cloud project: gcloud projects create PROJECT_ID Replace PROJECT_IDwith a name for the Google Cloud project you are creating.
- 
        Select the Google Cloud project that you created: gcloud config set project PROJECT_ID Replace PROJECT_IDwith your Google Cloud project name.
 
- 
  
    Verify that billing is enabled for your Google Cloud project. 
- 
  
  
    
      Enable the Artifact Registry, Cloud Build, Cloud Run Admin API, and Cloud Logging APIs: Roles required to enable APIs To enable APIs, you need the Service Usage Admin IAM role ( roles/serviceusage.serviceUsageAdmin), which contains theserviceusage.services.enablepermission. Learn how to grant roles.gcloud services enable artifactregistry.googleapis.com cloudbuild.googleapis.com run.googleapis.com logging.googleapis.com 
- 
    
        Grant roles to your user account. Run the following command once for each of the following IAM roles: roles/run.sourceDeveloper, roles/run.admin, roles/logging.viewergcloud projects add-iam-policy-binding PROJECT_ID --member="user:USER_IDENTIFIER" --role=ROLE Replace the following: - PROJECT_ID: Your project ID.
- USER_IDENTIFIER: The identifier for your user account. For example,- myemail@example.com.
- ROLE: The IAM role that you grant to your user account.
 
-  To set the default project for your Cloud Run service:
  gcloud config set project PROJECT_ID 
- If you are under a domain restriction organization policy restricting unauthenticated invocations for your project, you will need to access your deployed service as described under Testing private services. 
- 
Make sure that you have the Service Account User role granted on the service identity. By default, the service identity is the Compute Engine default service account. Grant the rolesTo grant access on the service identity resource, use the gcloud iam service-accounts add-iam-policy-bindingcommand, replacing the highlighted variables with the appropriate values:gcloud iam service-accounts add-iam-policy-binding SERVICE_ACCOUNT_EMAIL \ --member=user:PRINCIPAL \ --role=roles/iam.serviceAccountUser Replace the following: - SERVICE_ACCOUNT_EMAIL: the service account email address
      you are using as the service identity, such as:
         -  The Compute Engine default service account: PROJECT_NUMBER-compute@developer.gserviceaccount.com
-  A service account that you created: SERVICE_ACCOUNT_NAME@PROJECT_ID.iam.gserviceaccount.com
 
-  The Compute Engine default service account: 
- PRINCIPAL: the user identifier. This is typically the email address that is deploying the Cloud Run resource.
 
- SERVICE_ACCOUNT_EMAIL: the service account email address
      you are using as the service identity, such as:
         
- Grant the Cloud Build service account the following IAM role.
Click to view required roles for the Cloud Build service accountCloud Build automatically uses the Compute Engine default service account as the default Cloud Build service account to build your source code and Cloud Run resource, unless you override this behavior. For Cloud Build to build your sources, ask your administrator to grant Cloud Run Builder ( roles/run.builder) to the Compute Engine default service account on your project:gcloud projects add-iam-policy-binding PROJECT_ID \ --member=serviceAccount:PROJECT_NUMBER-compute@developer.gserviceaccount.com \ --role=roles/run.builder Replace PROJECT_NUMBERwith your Google Cloud project number, andPROJECT_IDwith your Google Cloud project ID. For detailed instructions on how to find your project ID, and project number, see Creating and managing projects.Granting the Cloud Run builder role to the Compute Engine default service account takes a couple of minutes to propagate. 
- Review Cloud Run pricing or estimate costs with the pricing calculator.
Write the sample function
To write an application, follow these steps:
Node.js
- Create a new directory named - helloworldand change directory into it:- mkdir helloworld cd helloworld
- Create a - package.jsonfile in the- helloworlddirectory to specify Node.js dependencies:
- Create an - index.jsfile in the- helloworlddirectory with the following Node.js sample:
Python
- Create a new directory named - helloworldand change directory into it:- mkdir helloworld cd helloworld
- Create a - requirements.txtfile in the- helloworlddirectory, to specify Python dependencies:- This adds packages needed by the sample. 
- Create a - main.pyfile in the- helloworlddirectory with the following Python sample:
Go
- Create a new directory named - helloworldand change directory into it:- mkdir helloworld cd helloworld
- Create a - go.modfile to declare the go module:
- Create an - hello_http.gofile in the- helloworlddirectory with the following Go code sample:
Java
- Create a new directory named - helloworldand change directory into it:- mkdir helloworld cd helloworld
- Create the following project structure to contain the source directory and source file: - mkdir -p ~/helloworld/src/main/java/functions touch ~/helloworld/src/main/java/functions/HelloWorld.java
- Update the - HelloWorld.javafile with the following Java code sample:
- Create a - pom.xmlfile in the- helloworlddirectory, and add the following Java dependencies:
Ruby
- Create a new directory named - helloworldand change directory into it:- mkdir helloworld cd helloworld
- Create a file named - app.rband paste the following code into it:
- Create a file named - Gemfileand copy the following into it:
- If you don't have Bundler 2.0 or greater installed, install Bundler. 
- Generate a - Gemfile.lockfile by running:- bundle install
PHP
- Create a new directory named - helloworldand change directory into it:- mkdir helloworld cd helloworld
- Create a file named - index.phpand paste the following code into it:
- If you aren't using Cloud Shell, create a - composer.jsonfile and paste the following code into it:
.NET
- Install .NET SDK. 
- From the console, create a new empty web project using the dotnet command. - dotnet new web -o helloworld-csharp
- Change directory to - helloworld-csharp:
- Replace the sample code in the project file - helloworld-csharp.csprojwith the following:
- Replace the sample code in - Program.csfile with the following:
Deploy the function
Important: This quickstart assumes that you have owner or editor roles in the project you are using for the quickstart. Otherwise, refer to the Cloud Run Source Developer role for the required permissions for deploying a Cloud Run resource from source.
To deploy your Cloud Run function, follow these steps:
- Deploy the function by running the following command in the directory that contains the sample code: - Node.js- gcloud run deploy nodejs-http-function \ --source . \ --function helloGET \ --base-image nodejs22 \ --region REGION \ --allow-unauthenticated- Replace REGION with the Google Cloud region of the service where you want to deploy your function. For example, - europe-west1.- Python- gcloud run deploy python-http-function \ --source . \ --function hello_get \ --base-image python313 \ --region REGION \ --allow-unauthenticated- Replace REGION with the Google Cloud region of the service where you want to deploy your function. For example, - europe-west1.- Go- gcloud run deploy go-http-function \ --source . \ --function HelloGet \ --base-image go125 \ --region REGION \ --allow-unauthenticated- Replace REGION with the Google Cloud region of the service where you want to deploy your function. For example, - europe-west1.- Java- Run the following command in the directory that contains the - pom.xmlfile:- gcloud run deploy java-http-function \ --source . \ --function functions.HelloWorld \ --base-image java21 \ --region REGION \ --allow-unauthenticated- Replace REGION with the Google Cloud region of the service where you want to deploy your function. For example, - europe-west1.- Ruby- gcloud run deploy ruby-http-function \ --source . \ --function hello_get \ --base-image ruby34 \ --region REGION \ --allow-unauthenticated- Replace REGION with the Google Cloud region of the service where you want to deploy your function. For example, - europe-west1.- PHP- gcloud run deploy php-http-function \ --source . \ --function helloGet \ --base-image php84 \ --region REGION \ --allow-unauthenticated- Replace REGION with the Google Cloud region of the service where you want to deploy your function. For example, - europe-west1.- .NET- gcloud run deploy csharp-http-function \ --source . \ --function HelloWorld.Function \ --base-image dotnet8 \ --region REGION \ --allow-unauthenticated- Replace REGION with the Google Cloud region of the service where you want to deploy your function. For example, - europe-west1.
- When the deployment is complete, the Google Cloud CLI displays a URL where the service is running. Open the URL in your browser to see the output of your function. 
Clean up
To avoid additional charges to your Google Cloud account, delete all the resources you deployed with this quickstart.
Delete your repository
Cloud Run doesn't charge you when your deployed service isn't in use. However, you might still be charged for storing the container image in Artifact Registry. To delete Artifact Registry repositories, follow the steps in Delete repositories in the Artifact Registry documentation.
Delete your service
Cloud Run services don't incur costs until they receive requests. To delete your Cloud Run service, follow one of these steps:
Console
To delete a service:
- In the Google Cloud console, go to Cloud Run: 
- Locate the service you want to delete in the services list, and click its checkbox to select it. 
- Click Delete. This deletes all revisions of the service. 
gcloud
To delete a service, run the following command:
gcloud run services delete SERVICE --region REGION
Replace the following:
- SERVICE: name of your service.
- REGION: Google Cloud region of the service.
Delete your test project
Deleting your Google Cloud project stops billing for all resources in that project. To release all Google Cloud resources in your project, follow these steps:
Delete a Google Cloud project:
gcloud projects delete PROJECT_ID
What's next
- To deploy a sample function to Cloud Run using the Google Cloud console, see Quickstart: Deploy a function to Cloud Run using the Google Cloud console. 
- To deploy functions and create triggers using the Google Cloud console and the Google Cloud CLI, see Deploy functions. 
- To view and delete existing functions, see Manage service revisions. 
- To build function containers in your own toolchain and deploy it to Cloud Run, see Build functions. 
- To create triggers with Eventarc, see Create triggers with Eventarc.