google-user-sync/README.md
Adam Moussa f807db2197
Some checks failed
Deploy / deploy (push) Has been cancelled
Add archive notice — merged into front-integrations (#4)
2026-05-12 13:35:42 -04:00

3.2 KiB

google-user-sync

Archived. This repo was merged into front-integrations on 2026-05-12. The handler was rewritten from JavaScript (CDK) to Python (SAM) to match the unified stack. The standalone CloudFormation stack and OIDC deploy role have been deleted.


A scheduled Lambda that pulls user profile data (job title, phone) from Google Workspace Admin Directory API and syncs it to Front teammate custom fields via the Front Core API. Runs weekdays at 6:00 AM ET via EventBridge.

Architecture

EventBridge (weekday cron, 6:00 AM ET)
    |
    v
Lambda (Node.js 22, arm64)
    |
    +-- Secrets Manager --> google-user-sync/google-service-account
    +-- Secrets Manager --> google-user-sync/front-api-token
    |
    +-- GET  Google Admin Directory API  -->  list users in target OUs
    +-- PATCH Front API /teammates/alt:email:{email}  -->  update custom_fields

AWS Resources

  • Stack: google-user-sync (CDK, us-east-1)
  • Lambda: google-user-sync — Node.js 22, arm64, 256 MB, 5 min timeout, 60-day log retention
  • EventBridge Rule: google-user-sync-daily — weekdays at 11:00 UTC
  • Secrets Manager: google-user-sync/google-service-account, google-user-sync/front-api-token

Prerequisites

1. Create Custom Fields in Front

  1. Gear icon > Company Settings > Custom Fields > Teammates tab
  2. Create two fields:
    • Job Title (String)
    • Phone (String)

2. Generate a Front API Token

  1. Gear icon > Company Settings > Developers > API tokens
  2. Create token with Shared resources scope (teammate read/write)

3. Create a Google Cloud Service Account

  1. Enable the Admin SDK API in Google Cloud Console
  2. Create a service account named front-directory-sync
  3. Create a JSON key and download it
  4. Enable Domain-Wide Delegation and copy the Client ID

4. Authorize in Google Workspace Admin

  1. Security > Access and Data Control > API Controls > Domain-Wide Delegation
  2. Add the Client ID with scope: https://www.googleapis.com/auth/admin.directory.user.readonly

5. Populate Google User Profiles

Ensure each user has their Job title and Phone filled in under Directory > Users.

6. Store Secrets in AWS Secrets Manager

aws secretsmanager create-secret \
  --name "google-user-sync/front-api-token" \
  --secret-string "YOUR_FRONT_API_TOKEN" \
  --region us-east-1

aws secretsmanager create-secret \
  --name "google-user-sync/google-service-account" \
  --secret-string file://path-to-service-account-key.json \
  --region us-east-1

Deployment

npm install
npx cdk deploy google-user-sync

Verification

aws lambda invoke \
  --function-name google-user-sync \
  --region us-east-1 \
  output.json && cat output.json

Check Front > Company Settings > Teammates > pick a user > Custom Fields to confirm Job Title and Phone are populated.

Maintenance

  • New teammates: Automatically picked up if they exist in both Google Workspace and Front with the same email.
  • Schedule changes: Update the EventBridge rule in lib/google-user-sync-stack.js.
  • Additional fields: Add as custom fields in Front, then update the field mapping in lambda/index.js.