For CI/CD deployments to Cloud Run, authentication design is a central part of operations. This article organizes the key ideas for deploying from GitHub Actions to GCP without storing a service-account key file in the repository.
Why Avoid Long-Lived Keys?
A common traditional approach is to store a GCP service-account JSON key in GitHub Secrets and use it with gcloud auth activate-service-account. The implementation is simple, but the risk of key leakage and the burden of key rotation remain.
With Workload Identity Federation (WIF), GCP can trust a GitHub OIDC token and deploy using short-lived credentials.
Key Configuration Points
- GCP: Create a Workload Identity Pool and Provider, then bind them with conditions on the GitHub repository (
owner/repo) and ref (for example,refs/heads/main). - IAM: Grant the deployment service account
roles/iam.workloadIdentityUserthrough the Pool. - GitHub Actions: Add
permissions: id-token: writeand usegoogle-github-actions/authfor federated authentication. - Deployment: After authentication, run
gcloud run deployor push to Artifact Registry.
Encoding the Pool, Provider, and service-account bindings as Terraform makes the same pattern easier to reuse across production and staging.
Connecting This to Cloud Run Operations
When user-facing and administrative services are separated and an external load balancer routes traffic by host, it is safer to split CI into service-specific deployment jobs as well. Operational procedures such as running database migrations before deployment and verifying Cloud Armor IP restrictions before a production release fit well with splitting the Actions workflows.
Summary
- Prefer WIF + OIDC over long-lived JSON keys.
- State repository and branch conditions explicitly in the Provider.
- Managing infrastructure (Terraform) and CI (GitHub Actions) in the same repository improves the reproducibility of environment setup.
Starter Kit
This implementation-ready kit turns the configuration described in this article into a deployable system. It includes a Rails application, Terraform, and GitHub Actions; once deployed, it provisions everything from Cloud SQL through an external HTTPS load balancer and Cloud Armor on GCP. Use it to get a new project off the ground quickly.