jobs — Architecture
The jobs/ directory contains Cloud Run Jobs for long-running batch operations that are not suitable for Pub/Sub Cloud Run Functions (time limit > 10 minutes, heavy file output, iterative processing).
Current Jobs
build-report
Generates XLSX, CSV, and PDF reports for the following report types:
| Report Type | Description |
|---|---|
iam-activity | IAM escalation history, role binding timeline |
resource-inventory | Full resource snapshot across all cloud projects |
security-posture | Open findings, remediation status, risk summary |
cost-summary | Estimated costs by resource type and project |
harvest-serp (removed)
Removed from core in the SEO extraction (see docs/seo-rank-tracking.md):
rank sweeping now ships inside the seo-rank-tracker app-store artifact
(domain/rank-sweep.ts) and runs via the artifact’s rank-sweep job from
its manifest.
verify-domain (removed)
Removed from core in the SEO extraction; domain verification now lives in
the seo-rank-tracker artifact’s gateway module.
Top-level
jobs/db-migrate/is a separate Cloud Run Job (not underservices/jobs/) that runs Firebase Data Connect SQL migrations from inside the VPC. See its owndocs/architecture.md.
Flow:
BuildReport command (Pub/Sub trigger) ↓Cloud Run Job invoked with tenantId + reportType + dateRange ↓Query read models from Postgres (@mnemose/db) ↓Generate XLSX + CSV via exceljs; PDF via pdfkit ↓Upload to GCS bucket: gs://mnemose-{env}-reports/{tenantId}/{reportId}.* ↓Emit ReportGenerated event with signed URLs (7-day TTL)Design Principles
- One job binary per job type — independent deployability, isolated dependencies
- Idempotent — jobs check for an existing report artifact before regenerating; re-invocation is safe
- Event-driven completion — jobs emit domain events when complete so the gateway can serve signed URLs without polling
Deployment
Each job deploys as a Cloud Run Job via the Pulumi stack in infra/. Jobs are triggered by Pub/Sub message delivery to a Cloud Run Job invocation endpoint.