A company uses Cloud Deploy for continuous delivery. They have a delivery pipeline with multiple targets: dev, staging, and prod. They want to require manual approval before deploying to prod. How should they configure this?
Approval gates are defined per target within the delivery pipeline, pausing a rollout before it advances. Placing a gate on the prod target blocks promotion until a human approves, satisfying the manual-approval constraint without altering dev or staging.
Why this answer
Google Cloud Deploy supports approval gates on targets, which pause a rollout and require manual approval before proceeding to the next target. Configuring an approval gate on the prod target in the delivery pipeline enforces the manual approval requirement natively.
Exam trap
The trap is overcomplicating the solution with custom Pub/Sub or Cloud Functions, when Cloud Deploy has a native approval gate feature on targets.
How to eliminate wrong answers
Option A is wrong because Cloud Build triggers are for building and testing, not for gating deployments; using a trigger to pause would be a custom workaround, not the intended mechanism. Option B is wrong because IAM conditions restrict who can perform actions but do not provide a manual approval step in the deployment flow. Option D is wrong because Pub/Sub and Cloud Functions could be used to build a custom approval system, but Cloud Deploy already provides a built-in approval gate, making this unnecessarily complex.