Skip to content

new submission pubsub parsing - #58

Merged
kyokukou merged 4 commits into
developfrom
CHECK-1413-new-submission-email
Sep 23, 2026
Merged

kyokukou merged 4 commits into
developfrom
CHECK-1413-new-submission-email

Conversation

@kyokukou

Copy link
Copy Markdown
Contributor

tests reading from the submit info topic and the form and data available

@github-actions

Copy link
Copy Markdown

Terraform plan · production

Plan: 1 to add, 0 to change, 0 to destroy.

Show full plan
data.google_project.this: Reading...
google_service_account.job: Refreshing state... [id=projects/arxiv-production/serviceAccounts/mod-notification-handler@arxiv-production.iam.gserviceaccount.com]
google_pubsub_topic.mod_notify: Refreshing state... [id=projects/arxiv-production/topics/mod-notify]
google_project_iam_member.job["roles/pubsub.subscriber"]: Refreshing state... [id=arxiv-production/roles/pubsub.subscriber/serviceAccount:mod-notification-handler@arxiv-production.iam.gserviceaccount.com]
google_project_iam_member.job["roles/secretmanager.secretAccessor"]: Refreshing state... [id=arxiv-production/roles/secretmanager.secretAccessor/serviceAccount:mod-notification-handler@arxiv-production.iam.gserviceaccount.com]
google_project_iam_member.job["roles/cloudsql.client"]: Refreshing state... [id=arxiv-production/roles/cloudsql.client/serviceAccount:mod-notification-handler@arxiv-production.iam.gserviceaccount.com]
google_project_iam_member.job["roles/run.invoker"]: Refreshing state... [id=arxiv-production/roles/run.invoker/serviceAccount:mod-notification-handler@arxiv-production.iam.gserviceaccount.com]
google_cloud_run_v2_job.jobs["mod_actions"]: Refreshing state... [id=projects/arxiv-production/locations/us-central1/jobs/mod-notification-handler]
google_cloud_run_v2_job.jobs["daily_update"]: Refreshing state... [id=projects/arxiv-production/locations/us-central1/jobs/mod-daily-digest]
google_pubsub_subscription.mod_actions: Refreshing state... [id=projects/arxiv-production/subscriptions/mod-notification-handler]
data.google_project.this: Read complete after 0s [id=projects/arxiv-production]
google_cloud_scheduler_job.jobs["mod_actions"]: Refreshing state... [id=projects/arxiv-production/locations/us-central1/jobs/mod-notification-handler-scheduler-trigger]
google_cloud_scheduler_job.jobs["daily_update"]: Refreshing state... [id=projects/arxiv-production/locations/us-central1/jobs/mod-daily-digest-scheduler-trigger]

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create

Terraform will perform the following actions:

  # google_project_iam_member.job["roles/eventarc.eventReceiver"] will be created
  + resource "google_project_iam_member" "job" {
      + etag    = (known after apply)
      + id      = (known after apply)
      + member  = "serviceAccount:mod-notification-handler@arxiv-production.iam.gserviceaccount.com"
      + project = "arxiv-production"
      + role    = "roles/eventarc.eventReceiver"
    }

Plan: 1 to add, 0 to change, 0 to destroy.

─────────────────────────────────────────────────────────────────────────────

Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.

@github-actions

Copy link
Copy Markdown

Terraform plan · development

Plan: 4 to add, 0 to change, 0 to destroy.

Show full plan
data.google_project.this: Reading...
google_service_account.job: Refreshing state... [id=projects/arxiv-development/serviceAccounts/mod-notification-handler@arxiv-development.iam.gserviceaccount.com]
google_pubsub_topic.mod_notify: Refreshing state... [id=projects/arxiv-development/topics/mod-notify]
google_pubsub_subscription.mod_actions: Refreshing state... [id=projects/arxiv-development/subscriptions/mod-notification-handler]
google_project_iam_member.job["roles/pubsub.subscriber"]: Refreshing state... [id=arxiv-development/roles/pubsub.subscriber/serviceAccount:mod-notification-handler@arxiv-development.iam.gserviceaccount.com]
google_project_iam_member.job["roles/secretmanager.secretAccessor"]: Refreshing state... [id=arxiv-development/roles/secretmanager.secretAccessor/serviceAccount:mod-notification-handler@arxiv-development.iam.gserviceaccount.com]
google_project_iam_member.job["roles/cloudsql.client"]: Refreshing state... [id=arxiv-development/roles/cloudsql.client/serviceAccount:mod-notification-handler@arxiv-development.iam.gserviceaccount.com]
google_project_iam_member.job["roles/run.invoker"]: Refreshing state... [id=arxiv-development/roles/run.invoker/serviceAccount:mod-notification-handler@arxiv-development.iam.gserviceaccount.com]
google_cloud_run_v2_job.jobs["daily_update"]: Refreshing state... [id=projects/arxiv-development/locations/us-central1/jobs/mod-daily-digest]
google_cloud_run_v2_job.jobs["mod_actions"]: Refreshing state... [id=projects/arxiv-development/locations/us-central1/jobs/mod-notification-handler]
data.google_project.this: Read complete after 1s [id=projects/arxiv-development]
google_cloud_scheduler_job.jobs["daily_update"]: Refreshing state... [id=projects/arxiv-development/locations/us-central1/jobs/mod-daily-digest-scheduler-trigger]
google_cloud_scheduler_job.jobs["mod_actions"]: Refreshing state... [id=projects/arxiv-development/locations/us-central1/jobs/mod-notification-handler-scheduler-trigger]

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create

Terraform will perform the following actions:

  # google_cloud_run_v2_service.new_subs[0] will be created
  + resource "google_cloud_run_v2_service" "new_subs" {
      + conditions              = (known after apply)
      + create_time             = (known after apply)
      + creator                 = (known after apply)
      + delete_time             = (known after apply)
      + deletion_policy         = "DELETE"
      + deletion_protection     = false
      + effective_annotations   = (known after apply)
      + effective_labels        = {
          + "arxiv-subsystem"            = "eust-modapi"
          + "arxiv-system"               = "eust"
          + "goog-terraform-provisioned" = "true"
        }
      + etag                    = (known after apply)
      + expire_time             = (known after apply)
      + generation              = (known after apply)
      + id                      = (known after apply)
      + ingress                 = "INGRESS_TRAFFIC_INTERNAL_ONLY"
      + labels                  = {
          + "arxiv-subsystem" = "eust-modapi"
          + "arxiv-system"    = "eust"
        }
      + last_modifier           = (known after apply)
      + latest_created_revision = (known after apply)
      + latest_ready_revision   = (known after apply)
      + launch_stage            = (known after apply)
      + location                = "us-central1"
      + name                    = "mod-notify-new-submission"
      + observed_generation     = (known after apply)
      + project                 = "arxiv-development"
      + reconciling             = (known after apply)
      + terminal_condition      = (known after apply)
      + terraform_labels        = {
          + "arxiv-subsystem"            = "eust-modapi"
          + "arxiv-system"               = "eust"
          + "goog-terraform-provisioned" = "true"
        }
      + traffic_statuses        = (known after apply)
      + uid                     = (known after apply)
      + update_time             = (known after apply)
      + uri                     = (known after apply)
      + urls                    = (known after apply)

      + scaling (known after apply)

      + template {
          + labels                           = {
              + "arxiv-subsystem" = "eust-modapi"
              + "arxiv-system"    = "eust"
            }
          + max_instance_request_concurrency = (known after apply)
          + service_account                  = "mod-notification-handler@arxiv-development.iam.gserviceaccount.com"
          + timeout                          = (known after apply)

          + containers {
              + args       = [
                  + "--target=handle_new_submission",
                  + "--source=app/new_subs/main.py",
                  + "--signature-type=cloudevent",
                ]
              + build_info = (known after apply)
              + command    = [
                  + "functions-framework",
                ]
              + image      = "gcr.io/arxiv-development/mod-notification-handler:5d896f34b770fb28066ec0c33ba6ab557a337d2b"

              + env {
                  + name  = "ARCHIVAL_EMAIL"
                    # (1 unchanged attribute hidden)

                  + value_source {
                      + secret_key_ref {
                          + secret  = "mod-notification-archival-email"
                          + version = "latest"
                        }
                    }
                }
              + env {
                  + name  = "CLASSIC_DB_URI"
                    # (1 unchanged attribute hidden)

                  + value_source {
                      + secret_key_ref {
                          + secret  = "modapi-dev-db-uri-for-cloudrun"
                          + version = "latest"
                        }
                    }
                }
              + env {
                  + name  = "ENV"
                  + value = "DEVELOP"
                }
              + env {
                  + name  = "GCP_PROJECT_ID"
                  + value = "arxiv-development"
                }
              + env {
                  + name  = "HALON_CREDS"
                    # (1 unchanged attribute hidden)

                  + value_source {
                      + secret_key_ref {
                          + secret  = "HALON_CREDS"
                          + version = "latest"
                        }
                    }
                }
              + env {
                  + name  = "MOD_REPLY_TO"
                    # (1 unchanged attribute hidden)

                  + value_source {
                      + secret_key_ref {
                          + secret  = "mod-notification-mod-reply-to"
                          + version = "latest"
                        }
                    }
                }
              + env {
                  + name  = "PYTHONPATH"
                  + value = "/app"
                }
              + env {
                  + name  = "REDIRECT_EMAILS"
                  + value = "True"
                }
              + env {
                  + name  = "REDIRECT_RECIPIENT"
                    # (1 unchanged attribute hidden)

                  + value_source {
                      + secret_key_ref {
                          + secret  = "test-email-group-address"
                          + version = "latest"
                        }
                    }
                }
              + env {
                  + name  = "SEND_EMAILS"
                  + value = "True"
                }

              + ports (known after apply)

              + resources {
                  + limits = {
                      + "cpu"    = "1000m"
                      + "memory" = "256Mi"
                    }
                }

              + startup_probe (known after apply)

              + volume_mounts {
                  + mount_path = "/cloudsql"
                  + name       = "cloudsql"
                }
            }

          + scaling {
              + max_instance_count = 5
              + min_instance_count = 0
            }

          + volumes {
              + name = "cloudsql"

              + cloud_sql_instance {
                  + instances = [
                      + "arxiv-development:us-east4:arxiv-db-dev",
                    ]
                }
            }
        }

      + traffic (known after apply)
    }

  # google_eventarc_trigger.new_subs[0] will be created
  + resource "google_eventarc_trigger" "new_subs" {
      + conditions              = (known after apply)
      + create_time             = (known after apply)
      + deletion_policy         = "DELETE"
      + effective_labels        = {
          + "arxiv-subsystem"            = "eust-modapi"
          + "arxiv-system"               = "eust"
          + "goog-terraform-provisioned" = "true"
        }
      + etag                    = (known after apply)
      + event_data_content_type = (known after apply)
      + id                      = (known after apply)
      + labels                  = {
          + "arxiv-subsystem" = "eust-modapi"
          + "arxiv-system"    = "eust"
        }
      + location                = "us-central1"
      + name                    = "mod-notify-new-submission-trigger"
      + project                 = "arxiv-development"
      + service_account         = "mod-notification-handler@arxiv-development.iam.gserviceaccount.com"
      + terraform_labels        = {
          + "arxiv-subsystem"            = "eust-modapi"
          + "arxiv-system"               = "eust"
          + "goog-terraform-provisioned" = "true"
        }
      + uid                     = (known after apply)
      + update_time             = (known after apply)

      + destination {
          + cloud_function = (known after apply)

          + cloud_run_service {
              + path    = "/"
              + region  = "us-central1"
              + service = "mod-notify-new-submission"
            }
        }

      + matching_criteria {
          + attribute = "type"
          + value     = "google.cloud.pubsub.topic.v1.messagePublished"
            # (1 unchanged attribute hidden)
        }

      + transport {
          + pubsub {
              + subscription = (known after apply)
              + topic        = "projects/arxiv-development/topics/submit-info"
            }
        }
    }

  # google_project_iam_member.job["roles/eventarc.eventReceiver"] will be created
  + resource "google_project_iam_member" "job" {
      + etag    = (known after apply)
      + id      = (known after apply)
      + member  = "serviceAccount:mod-notification-handler@arxiv-development.iam.gserviceaccount.com"
      + project = "arxiv-development"
      + role    = "roles/eventarc.eventReceiver"
    }

  # google_service_account_iam_member.pubsub_token_creator[0] will be created
  + resource "google_service_account_iam_member" "pubsub_token_creator" {
      + etag               = (known after apply)
      + id                 = (known after apply)
      + member             = "serviceAccount:service-874717964009@gcp-sa-pubsub.iam.gserviceaccount.com"
      + role               = "roles/iam.serviceAccountTokenCreator"
      + service_account_id = "projects/arxiv-development/serviceAccounts/mod-notification-handler@arxiv-development.iam.gserviceaccount.com"
    }

Plan: 4 to add, 0 to change, 0 to destroy.

─────────────────────────────────────────────────────────────────────────────

Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.

@kyokukou
kyokukou requested a review from bdc34 September 23, 2026 15:10
@kyokukou
kyokukou merged commit 13bf329 into develop Sep 23, 2026
4 checks passed
@kyokukou
kyokukou deleted the CHECK-1413-new-submission-email branch September 23, 2026 17:29
@kyokukou
kyokukou restored the CHECK-1413-new-submission-email branch September 23, 2026 17:38

This branch was successfully deployed

2 active deployments
development — efa423f5 Deployed Sep 23, 2026 by kyokukou via plan (development) #25
production — efa423f5 Deployed Sep 23, 2026 by kyokukou via plan (production) #25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants