Tanaka Soft

Secure Deployments from GitHub Actions to GCP — A Practical Guide to Workload Identity Federation

Key design points for deploying safely from GitHub Actions to GCP with Workload Identity Federation instead of long-lived credentials.

For CI/CD deployments to Cloud Run, authentication design is a central part of operations. This article organizes the key ideas for deploying from GitHub Actions to GCP without storing a service-account key file in the repository.

Why Avoid Long-Lived Keys?

A common traditional approach is to store a GCP service-account JSON key in GitHub Secrets and use it with gcloud auth activate-service-account. The implementation is simple, but the risk of key leakage and the burden of key rotation remain.

With Workload Identity Federation (WIF), GCP can trust a GitHub OIDC token and deploy using short-lived credentials.

Key Configuration Points

  1. GCP: Create a Workload Identity Pool and Provider, then bind them with conditions on the GitHub repository (owner/repo) and ref (for example, refs/heads/main).
  2. IAM: Grant the deployment service account roles/iam.workloadIdentityUser through the Pool.
  3. GitHub Actions: Add permissions: id-token: write and use google-github-actions/auth for federated authentication.
  4. Deployment: After authentication, run gcloud run deploy or push to Artifact Registry.

Encoding the Pool, Provider, and service-account bindings as Terraform makes the same pattern easier to reuse across production and staging.

Connecting This to Cloud Run Operations

When user-facing and administrative services are separated and an external load balancer routes traffic by host, it is safer to split CI into service-specific deployment jobs as well. Operational procedures such as running database migrations before deployment and verifying Cloud Armor IP restrictions before a production release fit well with splitting the Actions workflows.

Summary

  • Prefer WIF + OIDC over long-lived JSON keys.
  • State repository and branch conditions explicitly in the Provider.
  • Managing infrastructure (Terraform) and CI (GitHub Actions) in the same repository improves the reproducibility of environment setup.

Starter Kit

This implementation-ready kit turns the configuration described in this article into a deployable system. It includes a Rails application, Terraform, and GitHub Actions; once deployed, it provisions everything from Cloud SQL through an external HTTPS load balancer and Cloud Armor on GCP. Use it to get a new project off the ground quickly.

Rails on Cloud Run Starter Kit