Agent skill

Cloud Run Static Outbound Ip

by divinevideo in divinevideo/divine-mobile

Configure static outbound IP addresses for Google Cloud Run jobs/services.

MPL-2.0Auto-check passedData & Analytics

Install Cloud Run Static Outbound Ip

skills CLI
$ npx skills add divinevideo/divine-mobile --skill cloud-run-static-outbound-ip -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install divinevideo/divine-mobile cloud-run-static-outbound-ip --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cloud-run-static-outbound-ip .claude/skills/cloud-run-static-outbound-ip && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-run-static-outbound-ip
GitHub stars
266
Token cost
~1.5k tokens
SKILL.md length
326 words
Files
1
Skills in repo
103
Repo updated
First seen
Licence
MPL-2.0

At a glance

Configure static outbound IP addresses for Google Cloud Run jobs/services.

  • Works in 6 steps: Reserve Static IP Address → Create Cloud Router → Create Cloud NAT with Static IP → …
  • External service needs to whitelist your IP (archive.org
  • SKILL.md covers Problem, Context / Trigger Conditions, Solution and Verification, plus 5 more sections
  • Calls gcloud; reaches api.ipify.org

What it does

Cloud Run Static Outbound Ip is an agent skill from divinevideo/divine-mobile. Configure static outbound IP addresses for Google Cloud Run jobs/services. Use when: (1) External service needs to whitelist your IP (archive.org, APIs, firewalls), (2) Cloud Run requests appear from random/changing IPs, (3) Need consistent source IP for crawlers, scrapers, or API clients running on Cloud Run. Requires VPC connector + Cloud NAT + static IP reservation. Works for both Cloud Run services and jobs.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Data & Analytics, covering Web scraping and Cloud networking. It works with Cloud Run. The licence is MPL-2.0.

When your agent uses it

  • External service needs to whitelist your IP (archive.org
  • Cloud Run requests appear from random/changing IPs
  • Need consistent source IP for crawlers
  • API clients running on Cloud Run

Example prompts

  • “/cloud-run-static-outbound-ip”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Reserve Static IP Address
  2. Create Cloud Router
  3. Create Cloud NAT with Static IP
  4. Enable VPC Access API
  5. Create Serverless VPC Access Connector
  6. Update Cloud Run to Use VPC Connector

What it can do on your machine

Read from SKILL.md and the folder at commit 6487b05. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.ipify.org

    Also links to:

    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud Run Static Outbound Ip loads about 1.5k tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 326 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from divinevideo/divine-mobile at commit 6487b05, republished under its MPL-2.0 licence (© divinevideo). 326 words, ~1,455 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-run-static-outbound-ip/SKILL.md (or your agent's skills folder).
name
cloud-run-static-outbound-ip
description
Configure static outbound IP addresses for Google Cloud Run jobs/services. Use when: (1) External service needs to whitelist your IP (archive.org, APIs, firewalls), (2) Cloud Run requests appear from random/changing IPs, (3) Need consistent source IP for crawlers, scrapers, or API clients running on Cloud Run. Requires VPC connector + Cloud NAT + static IP reservation. Works for both Cloud Run services and jobs.
author
Claude Code
version
1.0.0
date
2026-01-26

Cloud Run Static Outbound IP Address

Problem

Cloud Run uses a shared pool of dynamic outbound IP addresses that change frequently and are shared across all Google Cloud customers. When external services need to whitelist your IP (for rate limit exemptions, firewall rules, or special access), you need a static, predictable outbound IP.

Context / Trigger Conditions

  • External service asks for IP address to whitelist
  • Cloud Run requests are being blocked by IP-based rate limiting
  • Need to identify your traffic to external APIs
  • Running crawlers/scrapers that need consistent source IP
  • Error messages about "IP not whitelisted" or similar

Solution

Architecture
Cloud Run → VPC Connector → VPC Network → Cloud NAT (static IP) → Internet
Step 1: Reserve Static IP Address
bash
gcloud compute addresses create [NAME]-nat-ip \
  --region=[REGION] \
  --description="Static IP for Cloud Run outbound traffic"

# Get the actual IP address
gcloud compute addresses describe [NAME]-nat-ip \
  --region=[REGION] \
  --format="value(address)"
Step 2: Create Cloud Router
bash
gcloud compute routers create [NAME]-router \
  --network=default \
  --region=[REGION]
Step 3: Create Cloud NAT with Static IP
bash
gcloud compute routers nats create [NAME]-nat \
  --router=[NAME]-router \
  --region=[REGION] \
  --nat-external-ip-pool=[NAME]-nat-ip \
  --nat-all-subnet-ip-ranges
Step 4: Enable VPC Access API
bash
gcloud services enable vpcaccess.googleapis.com
Step 5: Create Serverless VPC Access Connector
bash
gcloud compute networks vpc-access connectors create [NAME]-connector \
  --region=[REGION] \
  --network=default \
  --range=10.8.0.0/28 \
  --min-instances=2 \
  --max-instances=3 \
  --machine-type=e2-micro

Note: The IP range must not conflict with existing subnets. Use a /28 CIDR block.

Step 6: Update Cloud Run to Use VPC Connector

For Cloud Run Jobs:

bash
gcloud run jobs deploy [JOB-NAME] \
  --image=[IMAGE] \
  --region=[REGION] \
  --vpc-connector=[NAME]-connector \
  --vpc-egress=all-traffic \
  [... other flags ...]

For Cloud Run Services:

bash
gcloud run deploy [SERVICE-NAME] \
  --image=[IMAGE] \
  --region=[REGION] \
  --vpc-connector=[NAME]-connector \
  --vpc-egress=all-traffic \
  [... other flags ...]

Critical: --vpc-egress=all-traffic is required to route ALL outbound traffic through the VPC/NAT. Without this, only traffic to internal IPs uses the connector.

Verification

Test that outbound traffic uses the static IP:

bash
# Run a container that checks its external IP
gcloud run jobs execute [JOB-NAME] --region=[REGION] \
  --args="curl,-s,https://api.ipify.org"

Or add a test endpoint to your service that calls an IP echo service.

Example: Complete Setup Script

bash
#!/bin/bash
set -e

PROJECT_ID="my-project"
REGION="us-central1"
NAME="my-crawler"

# Reserve static IP
gcloud compute addresses create ${NAME}-nat-ip --region=$REGION

# Get and display the IP
STATIC_IP=$(gcloud compute addresses describe ${NAME}-nat-ip \
  --region=$REGION --format="value(address)")
echo "Static IP: $STATIC_IP"

# Create router
gcloud compute routers create ${NAME}-router \
  --network=default --region=$REGION

# Create NAT
gcloud compute routers nats create ${NAME}-nat \
  --router=${NAME}-router \
  --region=$REGION \
  --nat-external-ip-pool=${NAME}-nat-ip \
  --nat-all-subnet-ip-ranges

# Enable API and create connector
gcloud services enable vpcaccess.googleapis.com
gcloud compute networks vpc-access connectors create ${NAME}-connector \
  --region=$REGION \
  --network=default \
  --range=10.8.0.0/28 \
  --min-instances=2 \
  --max-instances=3 \
  --machine-type=e2-micro

echo "Setup complete! Use these flags in Cloud Run deployments:"
echo "  --vpc-connector=${NAME}-connector"
echo "  --vpc-egress=all-traffic"
echo ""
echo "Static IP for whitelisting: $STATIC_IP"

Cost Considerations

  • Static IP: Free while in use, ~$7/month if reserved but unused
  • VPC Connector: ~$7-20/month (2-3 e2-micro instances minimum)
  • Cloud NAT: ~$1/month + $0.045/GB processed

Total: ~$10-30/month depending on traffic volume.

Notes

  • All Cloud Run instances/jobs using the same VPC connector share the static IP
  • You can scale Cloud Run horizontally without changing IPs
  • VPC connector has throughput limits (~200-1000 Mbps depending on instance count)
  • For high-throughput needs, increase max-instances on the connector
  • Cloud SQL connections don't need to go through NAT (use Cloud SQL connector instead)
  • The VPC connector adds ~1-5ms latency to requests

Cleanup

To remove the setup:

bash
gcloud compute networks vpc-access connectors delete ${NAME}-connector --region=$REGION
gcloud compute routers nats delete ${NAME}-nat --router=${NAME}-router --region=$REGION
gcloud compute routers delete ${NAME}-router --region=$REGION
gcloud compute addresses delete ${NAME}-nat-ip --region=$REGION

References

© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/cloud-run-static-outbound-ip of divinevideo/divine-mobile.

Open the folder on GitHubat commit 6487b05

Compare with similar skills

Cloud Run Static Outbound Ip next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud Run Static Outbound Ip compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud Run Static Outbound Ip this skilldivinevideo/divine-mobile266—~1.5kAutomated safety check: PassMPL-2.0
Wp Static Clonejdevalk/skills105—~2.6kAutomated safety check: PassMIT
Tmuxtrpc-group/trpc-agent-go1.9k23 repos~868Automated safety check: PassApache-2.0
Ketch1broseidon/ketch7001 repos~3.9kAutomated safety check: PassMIT
Crawl4AI Web Scrapingsmallnest/goclaw5991 repos~2.5kAutomated safety check: PassMIT
Boss Zhipin Scrapereatmoreduck/boss-zhipin-scraper1.5k—~2.6kAutomated safety check: PassMIT

Similar skills

  • Wp Static Clone

    jdevalk/skills

    Clones a live WordPress (or other CMS-driven) site into a static HTML site deployable on any static host (Cloudflare Pages, Netlify, Vercel, S3+CloudFront, plain Apache/nginx).

    105 GitHub stars~2.6k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Tmux

    trpc-group/trpc-agent-go

    Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output.

    1.9k GitHub starsUsed in 23 repos~868 tokens
    Data & AnalyticsAuto-check passed
  • Ketch

    1broseidon/ketch

    Research skill for ketch — a fast stateless CLI for web search, OSS code search, curated library docs, page scraping, and site crawling; an optional MCP server exists for operators who want it, but…

    700 GitHub starsUsed in 1 repo~3.9k tokens
    Data & AnalyticsAuto-check passed
  • Crawl4AI Web Scraping

    smallnest/goclaw

    Scrapes sites, handles JavaScript-heavy pages and extracts structured data with Crawl4AI, through its crwl CLI or Python SDK, including schema-based extraction without an LLM.

    599 GitHub starsUsed in 1 repo~2.5k tokens
    Data & AnalyticsAuto-check passed
  • Boss Zhipin Scraper

    eatmoreduck/boss-zhipin-scraper

    Scrape BOSS直聘 (job listing site) via Chrome CDP. An agent skill from eatmoreduck/boss-zhipin-scraper.

    1.5k GitHub stars~2.6k tokensUpdated 10 days ago
    Data & AnalyticsAuto-check passed
  • Ax

    yusukebe/ax

    Use the ax CLI instead of curl + throwaway parsing scripts whenever you fetch a URL, explore an unknown web page, or extract structured data from HTML.

    719 GitHub starsUsed in 1 repo~918 tokens
    Data & AnalyticsAuto-check passed

More from divinevideo/divine-mobile

All 103 skills in this repo
  • Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

    266 GitHub stars~931 tokensUpdated today
    Auto-check passed
  • Art Direct

    divinevideo/divine-mobile

    Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.

    266 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Async Await Null Race Condition

    divinevideo/divine-mobile

    Fix "Null check operator used on a null value" errors when an object is set to null during an async await.

    266 GitHub stars~881 tokensUpdated today
    Auto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    266 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Bash Herestring Newline Secrets

    divinevideo/divine-mobile

    Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

    266 GitHub stars~791 tokensUpdated today
    Auto-check passed
  • Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).

    266 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Questions about Cloud Run Static Outbound Ip

What does Cloud Run Static Outbound Ip do?

Configure static outbound IP addresses for Google Cloud Run jobs/services. Cloud Run Static Outbound Ip is an agent skill from divinevideo/divine-mobile. Configure static outbound IP addresses for Google Cloud Run jobs/services.

When should I use Cloud Run Static Outbound Ip?

Cloud Run Static Outbound Ip fits situations like: external service needs to whitelist your IP (archive.org; cloud Run requests appear from random/changing IPs; need consistent source IP for crawlers; API clients running on Cloud Run.

How do I install Cloud Run Static Outbound Ip in Claude Code?

Run `npx skills add divinevideo/divine-mobile --skill cloud-run-static-outbound-ip -a claude-code`. Or copy the skill folder (.agents/skills/cloud-run-static-outbound-ip in divinevideo/divine-mobile) into .claude/skills/cloud-run-static-outbound-ip in your project. Claude Code loads it when a task matches its description.

How do I install Cloud Run Static Outbound Ip in Codex?

Run `npx skills add divinevideo/divine-mobile --skill cloud-run-static-outbound-ip -a codex`. Or copy the skill folder (.agents/skills/cloud-run-static-outbound-ip in divinevideo/divine-mobile) into .agents/skills/cloud-run-static-outbound-ip in your project. Codex loads it when a task matches its description.

Can I use Cloud Run Static Outbound Ip in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill cloud-run-static-outbound-ip -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-run-static-outbound-ip, .gemini/skills/cloud-run-static-outbound-ip, .github/skills/cloud-run-static-outbound-ip and .opencode/skills/cloud-run-static-outbound-ip in your project.

What does Cloud Run Static Outbound Ip need to run?

Going by SKILL.md and its folder, Cloud Run Static Outbound Ip needs the command-line tools its instructions call (gcloud).

Does Cloud Run Static Outbound Ip access the network?

SKILL.md names 2 domains. In commands or code: api.ipify.org; the agent is likely to contact it when it follows the instructions. As links in the text: cloud.google.com. This is read from the text; nothing was executed.

Is Cloud Run Static Outbound Ip safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloud Run Static Outbound Ip use?

Cloud Run Static Outbound Ip is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud Run Static Outbound Ip use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloud Run Static Outbound Ip?

Skills that share tags, products or a category with Cloud Run Static Outbound Ip: Wp Static Clone (jdevalk/skills, 105 stars), Tmux (trpc-group/trpc-agent-go, 1.9k stars), Ketch (1broseidon/ketch, 700 stars) and Crawl4AI Web Scraping (smallnest/goclaw, 599 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud Run Static Outbound Ip?

divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 266 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 9, 2026.

Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.