An Eventarc trigger declares your interest in a certain event
or set of events. You can configure event routing by
specifying filters for the trigger, including the event source, and the target
workflow.
Events are delivered in the CloudEvents format through an HTTP request. The
Workflows service converts the event to a JSON object (following the
CloudEvents specification) and passes
the event into the workflow execution as a
workflow runtime argument. Make
sure that the event size does not exceed the
resource limit. Events larger than the
maximum Workflows arguments size won't trigger workflow
executions.
These instructions show you how to configure event routing so that an execution
of your workflow is triggered in response to a direct
Backup for GKE event. For more
details, see the list of supported direct events.
Prepare to create a trigger
Before creating an Eventarc
trigger for a target workflow, complete the following tasks.
If applicable, enable the API related to the direct events. For example,
for Backup for GKE events, enable the
Backup for GKE API.
If you don't already have one, create a user-managed service account,
then grant it the roles and permissions necessary so that Eventarc
can manage events for a target workflow.
In the Google Cloud console, go to the Service Accounts
page.
In the Service account name field, enter a name. The Google Cloud console
fills in the Service account ID field based on this name.
In the Service account description field, enter a description. For
example, Service account for event trigger.
Click Create and continue.
To provide appropriate access, in the Select a role list, select
the required Identity and Access Management (IAM) roles to grant to your service
account. For more information, see
Roles and permissions for Workflows targets.
For additional roles, click addAdd another role and add each additional role.
Click Continue.
To finish creating the account, click Done.
gcloud
In the Google Cloud console, activate Cloud Shell.
At the bottom of the Google Cloud console, a
Cloud Shell
session starts and displays a command-line prompt. Cloud Shell is a shell environment
with the Google Cloud CLI
already installed and with values already set for
your current project. It can take a few seconds for the session to initialize.
Enable the Eventarc, Eventarc
Publishing, Workflows, and Workflow Executions APIs:
If applicable, enable the API related to the direct events. For example,
for Backup for GKE events, enable
gkebackup.googleapis.com.
If you don't already have one, create a user-managed service account,
then grant it the roles and permissions necessary so that
Eventarc can manage events for a target workflow.
Replace SERVICE_ACCOUNT_NAME with the name of the service account.
It must be between 6 and 30 characters, and can contain lowercase
alphanumeric characters and dashes. After you create a service account, you
cannot change its name.
You can create an Eventarc trigger with a deployed workflow as
the event receiver by using the Google Cloud CLI (gcloud or Terraform), or
through the Google Cloud console.
Console
In the Google Cloud console, go to the Eventarc
Triggers page.
This is the ID of the trigger and it must start with a letter. It can
contain up to 63 lowercase letters, numbers, or hyphens.
For the Trigger type, select
Google sources.
In the Event provider list, select
Backup for GKE.
Note that the event provider name used in the associated
Google Cloud documentation might not have a prefix
of Cloud or Google Cloud. For example, on the console,
Memorystore for Redis is referred to as
Google Cloud Memorystore for Redis.
In the Event type list, from the Direct events,
select an event type.
To specify the encoding of the event payload, in the Event data
content type list, select application/json or
application/protobuf.
Note that an event payload formatted in JSON is larger than one formatted
in Protobuf. This might impact reliability depending on your event
destination and its limits on event size. For more information, see
Known issues.
In the Region list, select the same region as the
Google Cloud service that is generating events.
In the Attribute value 1 field, depending on the
operator that you chose, type the exact value or apply a path pattern.
If more attribute filters are applicable, click
Add filter and specify the appropriate values.
Select the Service account that will invoke your service
or workflow.
Or, you can create a new service account.
This specifies the Identity and Access Management (IAM) service account email
associated with the trigger and to which you previously granted
specific roles required
by Eventarc.
In the Event destination list, select
Workflows.
Select a workflow.
This is the name of the workflow to pass events to. Events for a workflow
execution are transformed and passed to the workflow as runtime arguments.
Optionally, to add a label, you can click
addAdd label. Labels are key-value pairs that help you organize your
Google Cloud resources. For more information, see
What are labels?
Click Create.
After a trigger is created, the event source filters can't be modified.
Instead, create a new trigger and delete the old one. For more information,
see Manage triggers.
gcloud
You can create a trigger by running the gcloud eventarc triggers create
command along with required and optional flags.
TRIGGER: the ID of the trigger or a fully
qualified identifier.
LOCATION: the location of the Eventarc
trigger. Alternatively, you can set the eventarc/location
property; for example, gcloud config set eventarc/location us-central1.
To avoid any performance and data residency issues, the location must
match the location of the Google Cloud service that is generating events.
For more information, see
Eventarc locations.
DESTINATION_WORKFLOW: the ID of the
deployed workflow that receives the events
from the trigger. The workflow can be in any of the Workflows
supported
locations and does not need to be in the same
location as the trigger. However, the workflow must be in the same project
as the trigger.
DESTINATION_WORKFLOW_LOCATION (optional): the location in
which the destination workflow is deployed. If not specified, it is assumed that
the workflow is in the same location as the trigger.
EVENT_FILTER_TYPE: the identifier of the event.
An event is generated when an API call for the method succeeds.
For long-running operations, the event is only generated at the end of
the operation, and only if the action is performed successfully.
For a list of supported event types, see
Google event types supported by Eventarc.
COLLECTION_ID (optional): the
resource component that can act as
an event filter, and is one of the following:
backup
backupplan
restore
restoreplan
RESOURCE_ID: the identifier of the resource
used as the filtering value for the associated collection. For more
information, see Resource ID.
PATH_PATTERN: the
path pattern to apply when filtering
for the resource
EVENT_DATA_CONTENT_TYPE: (optional) the
encoding of the event payload.
This can be application/json or
application/protobuf. The default encoding is
application/json.
Note that an event payload formatted in JSON is larger than one formatted
in Protobuf. This might impact reliability depending on your event
destination and its limits on event size. For more information, see
Known issues.
SERVICE_ACCOUNT_NAME: the name of your user-managed service account.
PROJECT_ID: your Google Cloud project ID
Notes:
The --event-filters="type=EVENT_FILTER_TYPE"
flag is required. If no other event filter is set, events for all
resources are matched.
EVENT_FILTER_TYPE cannot be changed after
creation. To change EVENT_FILTER_TYPE, create a
new trigger and delete the old one.
Each trigger can have multiple event filters, comma delimited in one
--event-filters=[ATTRIBUTE=VALUE,...]
flag, or you can repeat the flag to add more filters. Only
events that match all the filters are sent to the destination. Wildcards
and regular expressions are not supported; however, when using the
--event-filters-path-pattern flag, you can define a resource
path pattern.
The --service-account flag is used to specify the Identity and Access Management
(IAM) service account email associated with the trigger.
This command creates a trigger called helloworld-trigger for
the event identified as google.cloud.gkebackup.backupPlan.v1.updated and
matches events for backupplan IDs
starting with my-backupplan-.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-07-17 UTC."],[],[]]