Skip to content

jobs — Architecture

The jobs/ directory contains Cloud Run Jobs for long-running batch operations that are not suitable for Pub/Sub Cloud Run Functions (time limit > 10 minutes, heavy file output, iterative processing).

Current Jobs

build-report

Generates XLSX, CSV, and PDF reports for the following report types:

Report TypeDescription
iam-activityIAM escalation history, role binding timeline
resource-inventoryFull resource snapshot across all cloud projects
security-postureOpen findings, remediation status, risk summary
cost-summaryEstimated costs by resource type and project

harvest-serp (removed)

Removed from core in the SEO extraction (see docs/seo-rank-tracking.md): rank sweeping now ships inside the seo-rank-tracker app-store artifact (domain/rank-sweep.ts) and runs via the artifact’s rank-sweep job from its manifest.

verify-domain (removed)

Removed from core in the SEO extraction; domain verification now lives in the seo-rank-tracker artifact’s gateway module.

Top-level jobs/db-migrate/ is a separate Cloud Run Job (not under services/jobs/) that runs Firebase Data Connect SQL migrations from inside the VPC. See its own docs/architecture.md.

Flow:

BuildReport command (Pub/Sub trigger)
↓
Cloud Run Job invoked with tenantId + reportType + dateRange
↓
Query read models from Postgres (@mnemose/db)
↓
Generate XLSX + CSV via exceljs; PDF via pdfkit
↓
Upload to GCS bucket: gs://mnemose-{env}-reports/{tenantId}/{reportId}.*
↓
Emit ReportGenerated event with signed URLs (7-day TTL)

Design Principles

  • One job binary per job type — independent deployability, isolated dependencies
  • Idempotent — jobs check for an existing report artifact before regenerating; re-invocation is safe
  • Event-driven completion — jobs emit domain events when complete so the gateway can serve signed URLs without polling

Deployment

Each job deploys as a Cloud Run Job via the Pulumi stack in infra/. Jobs are triggered by Pub/Sub message delivery to a Cloud Run Job invocation endpoint.