Skip to content
Back to skills

Cloud Scheduler Permission Denied

ASecurity

Fix Google Cloud Scheduler silently failing to trigger Cloud Run jobs with status code 7 (PERMISSION_DENIED). Use when: (1) Cloud Run jobs stop running but schedulers show ENABLED, (2) gcloud scheduler jobs describe shows lastAttemptTime but status.code: 7, (3) Jobs worked before but stopped after IAM changes or project updates. The scheduler service account needs roles/run.invoker on the project.

  • 265 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added May 27, 2026
documentationgobash

Works with

  • claude code

Security analysis

A100/100

Scanned May 27, 2026

npx -y skills add divinevideo/divine-mobile --skill cloud-scheduler-permission-denied --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cloud Scheduler Permission Denied?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cloud Scheduler Permission Denied
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/divinevideo-cloud-scheduler-permission-denied/badge)](https://www.skillsdirectory.com/skills/divinevideo-cloud-scheduler-permission-denied)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cloud-scheduler-permission-denied
description: |
  Fix Google Cloud Scheduler silently failing to trigger Cloud Run jobs with status code 7
  (PERMISSION_DENIED). Use when: (1) Cloud Run jobs stop running but schedulers show ENABLED,
  (2) gcloud scheduler jobs describe shows lastAttemptTime but status.code: 7,
  (3) Jobs worked before but stopped after IAM changes or project updates.
  The scheduler service account needs roles/run.invoker on the project.
author: Claude Code
version: 1.0.0
date: 2026-02-08
---

# Cloud Scheduler Permission Denied (Code 7)

## Problem
Cloud Scheduler jobs silently fail to trigger Cloud Run jobs. The scheduler shows as
ENABLED, attempts are made (lastAttemptTime updates), but Cloud Run jobs never start.
The only indicator is `status.code: 7` which means PERMISSION_DENIED.

## Context / Trigger Conditions
- Cloud Run jobs previously ran on schedule but stopped
- Dashboard shows jobs as "FAILED" or "DONE" with old timestamps
- `gcloud scheduler jobs describe <name>` shows:
  ```
  lastAttemptTime: '2026-02-08T14:00:03.316530Z'
  state: ENABLED
  status:
    code: 7
  ```
- No obvious errors in Cloud Logging for the scheduler

## Solution

1. **Identify the scheduler's service account**:
   ```bash
   gcloud scheduler jobs describe <scheduler-name> \
     --location=<region> \
     --project=<project> \
     --format="yaml(httpTarget.oauthToken.serviceAccountEmail)"
   ```

2. **Grant run.invoker role to that service account**:
   ```bash
   gcloud projects add-iam-policy-binding <project-id> \
     --member="serviceAccount:<service-account-email>" \
     --role="roles/run.invoker"
   ```

3. **Test by manually triggering the scheduler**:
   ```bash
   gcloud scheduler jobs run <scheduler-name> \
     --location=<region> \
     --project=<project>
   ```

4. **Verify the Cloud Run job started**:
   ```bash
   gcloud run jobs executions list \
     --region=<region> \
     --project=<project> \
     --limit=5
   ```

## Verification
After granting permissions and triggering:
- `status.code` should no longer be 7 on next attempt
- New Cloud Run job execution should appear in executions list
- Execution should show RUNNING status

## Example

```bash
# Check scheduler status - note code: 7
gcloud scheduler jobs describe profile-crawler-schedule \
  --location=us-central1 \
  --project=my-project

# Grant permission
gcloud projects add-iam-policy-binding my-project \
  --member="serviceAccount:my-scheduler@my-project.iam.gserviceaccount.com" \
  --role="roles/run.invoker"

# Test
gcloud scheduler jobs run profile-crawler-schedule \
  --location=us-central1 \
  --project=my-project
```

## Notes
- Status code 7 is gRPC's PERMISSION_DENIED - not documented prominently for Cloud Scheduler
- This commonly happens after:
  - Creating new service accounts
  - Migrating projects
  - IAM policy updates that remove inherited permissions
  - Using a custom service account instead of the default
- The scheduler will keep attempting (and failing) silently - no alerts by default
- Consider adding Cloud Monitoring alerts for scheduler failures

## References
- [Cloud Scheduler HTTP targets](https://cloud.google.com/scheduler/docs/http-target-auth)
- [Cloud Run IAM roles](https://cloud.google.com/run/docs/reference/iam/roles)
- [gRPC status codes](https://grpc.io/docs/guides/status-codes/)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…