Skip to main content

GitHub Actions

GitHub Actions runs the workflows that are the only way a change reaches Google Cloud: every plan, apply, image build and promotion is a workflow run triggered by a pull request, a merge, a release or a schedule. Every GCP repository except the GitOps repository, which ArgoCD reads, carries its own workflows.

What it does​

A workflow in .github/workflows/ runs jobs on a runner, either GitHub-hosted or self-hosted, selected by runs-on. Environments hold per-stage variables and can require reviewers before a job starts. With permissions: id-token: write a job obtains an OIDC token that a cloud trusts in place of a stored key. Concurrency groups decide whether a new run cancels or queues behind the one in flight.

How BuiltForProd uses it​

RepositoryWorkflows
acme-gcp-platform-baselineplan.yml (pull requests), apply.yml (merge, prod Environment), drift-detection.yml, runner-image.yml, notifier-image.yml
acme-gcp-blueprint-webapp-infra, -etl-infraplan.yml, apply.yml per stage in a dev, staging, prod matrix with an Environment per stage, drift-detection.yml
acme-gcp-blueprint-webapp-codeci.yml, cd-integration.yml, cd-frontend.yml, cd-release.yml, promote-prod.yml, and the gitops-pr action
acme-gcp-blueprint-etl-codeci.yml, cd-integration.yml, cd-release.yml
acme-gcp-blueprint-secretsplan.yml (dry-run sync per stage), sync.yml (path-aware sync, manual prune)

Sign-in. Every job that reaches Google Cloud authenticates through Workload Identity Federation as its repository's service account: a CI account sa-acme-<key>-ci in acme-core-auto, such as sa-acme-webapp-code-ci, or sa-acme-secrets-syncer in acme-core-security for the secrets repository. No service account key exists, and the organization policy forbids creating one. Infrastructure workflows then impersonate the target project's deployer through the providers root.hcl generates. The CI workflows of the code repositories never authenticate at all.

Runners. GitHub-hosted runners are the default: every call goes through Google APIs, and the cluster control planes are reached through their DNS-based endpoints. Plan, apply, drift and sync jobs read runs-on from the repository variable RUNNER_LABELS, which is needed only once a VPC Service Controls perimeter is enforced. The self-hosted runners are then Actions Runner Controller pods in the optional runner cluster in acme-core-auto (enable_github_runners), a scale set named acme-runners that scales from zero to five ephemeral runners; see GKE. Image builds always stay on GitHub-hosted runners.

Gates. The Baseline applies in one job in the prod Environment with the platform and DevOps leads as reviewers. The blueprint infrastructure applies each stage in its own Environment, and prod waits for its reviewers. Web app images reach prod only through promote-prod.yml, behind the prod Environment, and a GitOps pull request a person merges; ArgoCD prod then syncs by hand. The SPA and the ETL trigger deploy to prod from cd-release.yml behind the same Environment.

Drift. The Baseline plans with -detailed-exitcode at 01:00 UTC: on Monday every project folder, Tuesday to Friday the critical folders (core-network, core-identity, plat-dev, plat-staging, plat-prod). The blueprint infrastructure repositories plan dev, staging and prod daily at 05:00 UTC. Drift or a failed plan opens or updates an issue labeled drift.

Hygiene. Applies and deploys queue (cancel-in-progress: false); a new push cancels an outdated plan. Third-party actions are pinned by commit SHA. Terragrunt and tflint, and yq in the gitops-pr action, are downloaded at pinned versions and checked against their release SHA-256.

Terms you will see​

TermMeaning
EnvironmentA GitHub stage with its variables and, for prod, required reviewers.
CI service accountsa-acme-<key>-ci, the identity one repository's workflows act as.
RUNNER_LABELSThe repository variable that sends jobs to the self-hosted runners.
Deploy pull requestThe pull request a code workflow opens in the GitOps repository.
Drift issueThe issue labeled drift that a scheduled plan opens on a difference.

Where to read more​