GitHub Actions
GitHub Actions runs the workflows that are the only way a change reaches Google Cloud: every plan, apply, image build and promotion is a workflow run triggered by a pull request, a merge, a release or a schedule. Every GCP repository except the GitOps repository, which ArgoCD reads, carries its own workflows.
What it does
A workflow in .github/workflows/ runs jobs on a runner, either GitHub-hosted or self-hosted, selected by runs-on. Environments hold per-stage variables and can require reviewers before a job starts. With permissions: id-token: write a job obtains an OIDC token that a cloud trusts in place of a stored key. Concurrency groups decide whether a new run cancels or queues behind the one in flight.
How BuiltForProd uses it
| Repository | Workflows |
|---|---|
acme-gcp-platform-baseline | plan.yml (pull requests), apply.yml (merge, prod Environment), drift-detection.yml, runner-image.yml, notifier-image.yml |
acme-gcp-blueprint-webapp-infra, -etl-infra | plan.yml, apply.yml per stage in a dev, staging, prod matrix with an Environment per stage, drift-detection.yml |
acme-gcp-blueprint-webapp-code | ci.yml, cd-integration.yml, cd-frontend.yml, cd-release.yml, promote-prod.yml, and the gitops-pr action |
acme-gcp-blueprint-etl-code | ci.yml, cd-integration.yml, cd-release.yml |
acme-gcp-blueprint-secrets | plan.yml (dry-run sync per stage), sync.yml (path-aware sync, manual prune) |
Sign-in. Every job that reaches Google Cloud authenticates through Workload Identity Federation as its repository's service account: a CI account sa-acme-<key>-ci in acme-core-auto, such as sa-acme-webapp-code-ci, or sa-acme-secrets-syncer in acme-core-security for the secrets repository. No service account key exists, and the organization policy forbids creating one. Infrastructure workflows then impersonate the target project's deployer through the providers root.hcl generates. The CI workflows of the code repositories never authenticate at all.
Runners. GitHub-hosted runners are the default: every call goes through Google APIs, and the cluster control planes are reached through their DNS-based endpoints. Plan, apply, drift and sync jobs read runs-on from the repository variable RUNNER_LABELS, which is needed only once a VPC Service Controls perimeter is enforced. The self-hosted runners are then Actions Runner Controller pods in the optional runner cluster in acme-core-auto (enable_github_runners), a scale set named acme-runners that scales from zero to five ephemeral runners; see GKE. Image builds always stay on GitHub-hosted runners.
Gates. The Baseline applies in one job in the prod Environment with the platform and DevOps leads as reviewers. The blueprint infrastructure applies each stage in its own Environment, and prod waits for its reviewers. Web app images reach prod only through promote-prod.yml, behind the prod Environment, and a GitOps pull request a person merges; ArgoCD prod then syncs by hand. The SPA and the ETL trigger deploy to prod from cd-release.yml behind the same Environment.
Drift. The Baseline plans with -detailed-exitcode at 01:00 UTC: on Monday every project folder, Tuesday to Friday the critical folders (core-network, core-identity, plat-dev, plat-staging, plat-prod). The blueprint infrastructure repositories plan dev, staging and prod daily at 05:00 UTC. Drift or a failed plan opens or updates an issue labeled drift.
Hygiene. Applies and deploys queue (cancel-in-progress: false); a new push cancels an outdated plan. Third-party actions are pinned by commit SHA. Terragrunt and tflint, and yq in the gitops-pr action, are downloaded at pinned versions and checked against their release SHA-256.
Terms you will see
| Term | Meaning |
|---|---|
| Environment | A GitHub stage with its variables and, for prod, required reviewers. |
| CI service account | sa-acme-<key>-ci, the identity one repository's workflows act as. |
RUNNER_LABELS | The repository variable that sends jobs to the self-hosted runners. |
| Deploy pull request | The pull request a code workflow opens in the GitOps repository. |
| Drift issue | The issue labeled drift that a scheduled plan opens on a difference. |
Where to read more
- GCP Enterprise Baseline overview and the GCP Web App, Data and ETL and Secrets Blueprint overviews.
- Workload Identity Federation for the identities.
- GitOps for the delivery model.