> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/runtime-security/install/deploy-defender/app-embedded/deploy-app-embedded-new-gcr.md).

# Deploy App-Embedded Defender in Google Cloud Run

Follow these steps to deploy and validate the Prisma Cloud App-Embedded Defender in Google Cloud Run (GCR).

## Prerequisites

* A Google Cloud account.
* A Google Artifact Registry (GAR) remote repository for hosting the Prisma Cloud App-Embedded Defender image.
* The Google Cloud CLI (gcloud) installed and configured.
* Access to the Prisma Cloud Console.
* A YAML file that defines the GCR instance you want to protect.

## Deployment Procedure

Follow these steps to generate and deploy the YAML file required for deploying your GCR instance with the Prisma Cloud app-embedded defender for GCR.

### Host the App-Embedded Defender Image in a Google Artifact Registry repository

Follow these steps to download the Prisma Cloud app-embedded defender for GCR image and push it your Google Artifact Registry (GAR) repository:

1. Log in to the Prisma Cloud Console.
2. Open **Manage > System > Utilities > General Utilities > Defender Image**.
3. Download the app-embedded defender image.
4. Push the downloaded image to your GAR repository.

   The defender image must be in a GAR repository within the same project as your Cloud Run service.
5. Copy the URL of the GAR image for the next step.

### Configure the defender and generate the deployment YAML

1. Go to **Manage > Defenders > Defenders: Deployed**.
2. Select **Manual deploy**.
3. Open **Basic Settings**:
   1. Select **Single Defender** as the deployment method.
   2. Select **Container Defender App-Embedded** as the defender type.
   3. Select **Cloud Run service** as the deployment type.
   4. In the **Privacy and security** section, paste the URL of the GAR image copied in the previous procedure.

      The defender image must be in a GAR repository within the same project as your Cloud Run service.
4. Generate the protected deployment YAML: Submit a valid GCR deployment YAML to the Prisma Cloud Console. The console modifies this YAML to include the defender’s init container and other essential settings.
   1. Enter a valid GCR deployment YAML in **Insert deployment definition**.

      For more information about GCR deployment YAML, see [Deploying a service with sidecar containers](https://cloud.google.com/run/docs/deploying#yaml_2) and [Cloud Run YAML Reference](https://cloud.google.com/run/docs/reference/yaml/v1).
   2. Click **Generate protected deployment definition**.
   3. The output is displayed in **Generated deployment definition**. Copy the YAML generated by Prisma Cloud Console for deployment in your GCR instance.

### Deploy the generated YAML in GCR

After the console processes your original YAML file, it will return a modified version that includes the defender instrumentation.

1. Save the YAML generated by the Prisma Cloud Console to a file. For example, `defended-service.yaml`.
2. Apply this YAML file in GCR by running the following command: `gcloud run services replace defended-service.yaml -region <REGION_NAME> --platform <PLATFORM_NAME> --project <PROJECT_NAME>`

## Validate Defender Visibility

Confirm the successful deployment of your GCR instance and the defender in your Google Cloud environment and the Prisma Cloud Console.

### In Google Cloud:

1. To verify that the instance and the app-embedded defender are running, run: `gcloud run services describe <SERVICE_NAME> --region=<REGION_NAME> --project <PROJECT_NAME> --format=yaml`

And confirm that the a status block that includes:

* `latestReadyRevisionName`: The name of the revision that’s ready to serve requests.
* `url`: The URL endpoint for the service.
* `conditions`: For a healthy service, you’ll see a condition with `type: Ready` and `status: "True"`.

### In the Prisma Cloud Console

1. Onboard the GCR instance in Prisma Cloud. See the Prisma Cloud documentation for account setup procedures.
2. Go to **Radar > Defenders > Deployed defenders**.
3. Filter the view to locate your new Defender. It will be uniquely identified by a combination of its cloud provider (Google), region, container name, and revision.

## Run Cloud Discovery

Run a cloud discovery scan to ensure the Prisma Cloud Console accurately correlates the running defender with the discovered GCR service.

1. In the Prisma Cloud Console, manually initiate a cloud discovery scan for the relevant GCR service.
2. When the scan is complete, go to the **Radar** view.
3. Locate the **Google Cloud Run Service** asset for your deployment and confirm its status in the **Is Defended** column.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/runtime-security/install/deploy-defender/app-embedded/deploy-app-embedded-new-gcr.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
