m Moritz Bauer — writing on digital data
◦ Essay ·

Auto Updates for Serverside Google Tag Manager on Cloud Run

How to automate updates of the sGTM Docker image running on Cloud Run with a Cloud Function.

TLDR: I wrote a Cloud Function that automatically updates the sGTM Docker image. Jump to the solution ->

Checking the current sGTM version

Anyone running the serverside Google Tag Manager (sGTM) on Cloud Run has probably already encountered the update notice in the sGTM web interface. It is shown when an outdated version of the gtm-cloud-image Docker image is running. The currently deployed version of the Docker image can be verified through its sha256 value. To do that, go to your Cloud Run service in the Google Cloud Platform, open the latest revision, and look for the image URL of the active revision on the right-hand side.

In this case we note down 89c94351489c72180c1ba3d7ec9a795e3bf6b0729d554709044d70bd5c7a6ce3. Next, we check the sha256 value of the current image.

We open the Container Registry overview at gcr.io/cloud-tagging-10302018/gtm-cloud-image and look for the version tagged “stable”.

We see the version named “89c94351489c”. Sharp-eyed readers will already have noticed that this string matches the beginning of the sha256 value of the currently deployed image. Inspecting the version more closely shows the full sha256 value.

Now we can compare the two sha256 values and confirm that the latest “stable” version of gtm-cloud-image is deployed in our Cloud Run service. If that’s not the case, we only need to deploy a new revision of our Cloud Run service to update to the latest version, since we very likely set the image URL to gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable.

Automatic updates with Cloud Function

Because we don’t want to manually check for new versions and deploy a new revision, I wrote a Cloud Function that performs the steps described above automatically. It can easily be triggered on a fixed schedule, e.g. weekly, with Cloud Scheduler.

To deploy the Cloud Function into your GCP project, I recommend the following steps:

  • Clone / download the GitHub repository
  • Install dependencies like the gcloud CLI and functions-framework-nodejs
  • Test the Cloud Function locally on localhost via npm start — POST request with body {project_id: PROJECT_ID, region: REGION, service_name: SERVICE_NAME}
  • Deploy via gcloud builds submit directly into the configured GCP project

For the deployment via gcloud builds submit to work, the Cloud Functions Developer role must be enabled for Cloud Build.

Example

When I check the Cloud Run service for my sGTM at moritzbauer.info, I get the following logs:

No update is needed because the sha256 values match.

If they didn’t match, the Cloud Function would deploy a new revision including environment variables like CONTAINER_CONFIG or PREVIEW_SERVER_URL and any health checks.

Conclusion

Automatic updates to the latest “stable” version of the gtm-cloud-image Docker image make sense when a larger number of Cloud Run services have to be managed. Especially in an agency context, this is a way to ensure that even after the engagement, the image stays up-to-date and security issues and bugs are addressed. If a deployment of a new revision fails, traffic is automatically routed to the last healthy revision, so an outage should be impossible.

In the future I’ll add this Cloud Function to my Terraform deployment script for the serverside Google Tag Manager.