Skip to main content

Static Asset Route

StaticAssetRoute​

Defines the high-level intent for serving static content via the public ingress layer.

Maps URL path prefixes on a host to static content backed by either a Bucket manifest or a SiteConfig (a target: CDN application), compiled into the parent ingress's HTTP(S) load balancer as bucket-backed URL-map paths (a google_compute_backend_bucket with Cloud CDN) for low-latency, edge-optimized delivery of frontend assets and single-page apps.

Behavior worth knowing:

  • Host: the route is served at <metadata.name>.<ingress-domain>. Naming a StaticAssetRoute and an HttpRoute the same shares one host — the engine merges their paths into a single URL-map path matcher, sorted by specificity, so specific API prefixes hit backend services while a catch-all / serves the static bundle. Do not declare a / prefix on both a static route and an HTTP route on the same host.
  • Auth: bucket-backed paths are served by a backend bucket, which cannot be gated with IAP/GCIP/identity at the load balancer, so static content is served publicly (see BucketRouteConfig.authentication).
  • Single-page apps: set BucketRouteConfig.not_found_page (defaulted to /index.html for site_config targets) so a 404 serves the app entry with a 200 and the client-side router handles deep links on refresh.
PropertyTypeDescription
apiVersionstringAPI schema version. Pins the manifest to a specific schema contract for backward-compatibility. Must be the constant lowops.manifests.v1.
kindstringResource kind discriminator. Identifies this document as a StaticAssetRoute so the engine routes it to the correct defaulter, validator, computer, and executor. Must be the constant StaticAssetRoute.
metadatamapClassification labels and graph linkage. Free-form key/value pairs used to classify the manifest. Certain reserved keys (e.g. name, project) are read by the engine to resolve this manifest's identity and its parent ingress (PublicIngress or PrivateIngress) in the dependency graph.
specSpecDesired static asset route configuration. The authoritative, user-authored specification for this StaticAssetRoute. See Spec.

Spec​

User-defined URL-path-to-static-content mappings.

The authored intent for serving static content: which URL path prefixes are backed by which storage bucket or CDN application, and how not-found requests are handled. The engine folds these into the parent ingress's load-balancer configuration as bucket-backed URL-map paths.

PropertyTypeDescription
descriptionstringHuman-readable description of this route. Optional free text describing the purpose of the route. Not consumed by the engine's provisioning logic; surfaced in generated documentation and used as context by AI assistants when reasoning about the manifest.
pathslist of PathsEntryURL-path-to-static-content routing map. Maps a URL path prefix (the map key, e.g. / for a single-page app or /images for assets) to the content that serves it — a Bucket manifest (name) or a CDN application (site_config), plus optional single-page-app fallback (not_found_page); see BucketRouteConfig. Consumed during computation of the parent ingress to build load-balancer bucket-backed paths, and validated so each path names exactly one existing bucket or SiteConfig in the parent Project.

PathsEntry​

PropertyTypeDescription
keystring
valueBucketRouteConfig

BucketRouteConfig​

Configures authorization rules specifically for bucket backends.

Affects the associated URL map routing and attached authz extensions when a Load Balancer path serves static assets directly from GCS. Backing target and serving behavior for one static path.

Describes how a single URL path prefix under a StaticAssetRoute is served: which storage bucket (name) or CDN application (site_config) backs it, and how a not-found request is handled (not_found_page). The engine compiles each entry into a bucket-backed path on the parent ingress's HTTP(S) load balancer — a google_compute_backend_bucket with Cloud CDN enabled, wired into the URL map. Because the backend is a bucket (not a backend service), the load balancer cannot apply IAP/GCIP/identity gating to it, so static paths are served publicly; a single-page app that needs auth must authenticate client-side (e.g. via GCIP) rather than at the edge.

PropertyTypeDescription
namestringBacking Bucket manifest name. Name of the Bucket manifest whose static assets are served directly by this Load Balancer path. Mutually exclusive with site_config: set exactly one. Validated to exist in the parent Project.
authenticationlist of RouteRuleAuthenticationConfigAuthentication configuration. NOT ENFORCED for static (bucket-backed) paths. Present only for schema symmetry with HTTP routes. A StaticAssetRoute path is served by a backend BUCKET, which the load balancer cannot gate with IAP/IDENTITY_PROVIDER/INTERNAL auth (only backend services carry IAP). This field is therefore ignored and the content is served publicly — authenticate a gated single-page app client-side instead.
authorizationlist of ComputedAuthorizationAccessRuleCheckAuthorization configuration. NOT ENFORCED for static (bucket-backed) paths. Present only for schema symmetry with HTTP routes. As with authentication, bucket-backed paths cannot be gated at the load balancer, so this field is ignored and the content is served publicly.
siteConfigstringBacking SiteConfig (CDN application) target. Name of a SiteConfig manifest (a target: CDN application) whose serving bucket backs this Load Balancer path. Mirrors how HttpRouteRuleActionDestination targets a deployment_config/virtual_machine: the engine resolves the SiteConfig's engine-owned serving bucket (whose real name is server-assigned) into the backend bucket, so authors reference the app by name rather than the physical bucket. Mutually exclusive with name: set exactly one. Validated to exist in the parent Project.
notFoundPagestringPage served for unmatched requests (single-page-app fallback). When set, a request that misses (the bucket returns 404 — e.g. a client-side route like /license-keys on refresh) is served this bucket object in place with an overridden 200 status (not a browser redirect — the URL is unchanged), so the SPA router handles the path. Implemented as a URL-map CustomErrorResponsePolicy on this path's rule. Set it to the app's entry file (/index.html is the usual value, but it can differ — e.g. /app.html, or /admin/index.html for a sub-app). Leave empty on a plain asset host (e.g. /images) to return real 404s. Defaults to /index.html for site_config (CDN app) targets, which are SPAs.

ComputedAuthorizationAccessRuleCheck​

Represents a computed access check for a route rule.

Maps an expected identity tuple (namespace, relation, object) that the AuthZ extension must validate during the request flow.

PropertyTypeDescription
namespacestringThis value is a direct reflection of 'spec.authorization.namespace' from a child 'HttpRoute' or 'GrpcRoute' manifest.
relationstringThis value is a direct reflection of 'spec.authorization.relation' from a child 'HttpRoute' or 'GrpcRoute' manifest.
objectstringThis value is a direct reflection of 'spec.authorization.object' from a child 'HttpRoute' or 'GrpcRoute' manifest.

RouteRuleAuthenticationConfig​

Configures authentication exceptions or specifics for a route rule.

Translates into localized Gateway or Load Balancer configurations dictating how auth assertions are evaluated for specific matched paths.

PropertyTypeDescription
typestringAuthentication mode. How the route rule is authenticated: IDENTITY_PROVIDER restricts access to named identity providers (see tenants), while INTERNAL restricts to internal callers. Validated against the manifest's declared identity providers during route/ingress validation.
tenantslist of stringAllowed identity providers. A list of IdentityProvider names permitted to access this route. Only applicable when type is IDENTITY_PROVIDER; each entry is validated to reference an existing provider.