Open source · Apache-2.0

Cloud Run deployments from one file.

runway builds your app, creates what it needs (identity, grants, secrets, buckets, tags), rolls it out and manages its traffic, from a runway.yaml next to your code. No state file. No cluster.

brew install echaouchna/tap/runway

macOS and Linux. Also as binaries, a container image or from source.

~/hello
$ runway plan --stage prod
~ update hello-prod
    ~ memory: 512Mi -> 1Gi
    + secrets.API_KEY: api-key@3
  + grant secretAccessor on api-key to hello-run

$ runway deploy --stage prod --preview feature/login
==> Building hello from . (image exists → skip)
==> Updating Cloud Run service hello-prod
✓ hello-prod updated in 38s
Preview:  https://feature-login---hello-prod-…run.app
Traffic:  100% hello-prod-00012 · 0% feature-login

$ runway deploy --stage prod --traffic 10   # canary
$ runway traffic --stage prod --promote
Demo

See it run, in under a minute

One runway.yaml, then the offline diagram, a first deploy, an exact plan, a URL per branch, a canary and pruning. Pause any time and copy what you see. Cloud output uses sample names (my-gcp-project); waits are shortened.

~/hello
Features

Everything a Cloud Run service needs, nothing to glue

One configuration covers the build, the runtime identity and its least-privilege grants, secrets, storage, probes, scaling, access and traffic. Every step reads the live project first and changes only what differs.

Builds that skip themselves

Dockerfile or buildpacks on Cloud Build. Images are content-addressed: same source and base images, no rebuild.

A URL per branch

--preview $BRANCH deploys a revision with its own URL and no traffic. Merge to main and the release gets the traffic.

Canaries and rollback

--traffic 10, watch, runway traffic --promote. Roll back with one command. No revision churn.

Secrets without the dance

Declared secrets are created empty, the right people can fill them, and the deploy waits (with the exact command) until they have a value.

Least privilege by default

A runtime service account per service, roles on exactly one dataset, bucket or secret, private by default, IAP when you want it.

Org policies welcome

Tags bound to the service and awaited until effective; a first deploy that satisfies run.allowedIngress conditions.

Exact plans

runway plan diffs config, image, traffic and grants against the live service, and says when something is only known at deploy time.

Observability built in

otel_collector: {} adds Google's OpenTelemetry Collector as a sidecar with the roles and APIs it needs. runway logs --follow.

No state, no cluster

The project is the state. Ownership labels keep runway away from what it did not create. Undeploy keeps your data.

How it works

Describe it once. Re-run forever.

1
Write runway.yaml

Stages, build, identity, secrets, access. runway init scaffolds one.

2
Plan

See the exact changes against the live project, read-only.

3
Deploy

APIs, buckets, secrets, accounts, grants, build, rollout, health, traffic, access: in dependency order, each step idempotent.

4
Same command in CI

Workload Identity Federation, a container image, JSON output and stable exit codes.

runway.yaml
version: 1
app: hello
provider:
  project: my-project
  region: europe-west1
  enable_apis: true
  create_build_resources: true
secrets:
  api-key: { adders: [group:devs@example.com] }
service:
  source: .            # Dockerfile or buildpacks
  health_check: { path: /healthz }
  service_account: "hello-run@${project}.iam.gserviceaccount.com"
  identity:
    create: true
    roles:
      - { role: roles/storage.objectUser, bucket: my-data }
  secrets:
    API_KEY: { secret: "${secrets.api-key}" }
  iap: { members: [group:devs@example.com] }
stages:
  dev: {}
  prod: { service: { min_instances: 1 } }
Compare

Where runway fits

Keep Terraform for shared platform resources (networks, load balancers, DNS) and Kubernetes GitOps for Kubernetes. runway takes the part that changes every day: the Cloud Run application.

CI scripts + TerraformGitOps (Argo CD)runway
What the app team maintainsCI YAML + HCL, often in several reposCI + manifests + controller CRDsone runway.yaml
Extra infrastructurestate buckets, Terraform pipelinea cluster and controllersnone
Branch previews, canariesbuild it yourselfKubernetes-centricbuilt in
Secretscreated by Terraform, filled by handsecrets operatorcreated, granted, checked before deploy
Driftnext applyhealed continuouslynext plan / deploy

Ship your next Cloud Run service in minutes.

Read the docs, deploy your first app, and tell us what you think.