0.5.4 — clear the managed base image on every Cloud Run deploy #12
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| ################################### | |
| # | |
| # GitHub Actions Workflow File - Deploy the Python API to GCP Cloud Run | |
| # | |
| # This workflow deploys the API to Google Cloud Run whenever a release is | |
| # published — the same deliberate, named act that ships your database | |
| # migrations. Publish a release, and both robots run: the schema and the | |
| # code that expects it ship together. | |
| # | |
| # Until the one-time setup below is done, the workflow skips itself quietly | |
| # (a green tick, nothing deployed) — a release made before deployment is | |
| # configured is never marked as a failure. | |
| # | |
| # One-time setup (the course walks through this in "The Production Backend"): | |
| # | |
| # 1. Fill in the three values in the `env:` block below — your Cloud Run | |
| # service name, region, and production Supabase URL. | |
| # | |
| # 2. Create a deployer service account and hand its key to GitHub. The key | |
| # is the ONLY GitHub secret this workflow needs (it carries the project | |
| # id inside it): | |
| # | |
| # PROJECT=<your-gcp-project-id> | |
| # gcloud iam service-accounts create github-deployer \ | |
| # --display-name="GitHub Actions deployer" --project=$PROJECT | |
| # for role in roles/run.admin roles/iam.serviceAccountUser \ | |
| # roles/cloudbuild.builds.editor roles/artifactregistry.admin \ | |
| # roles/storage.admin roles/serviceusage.serviceUsageConsumer; do | |
| # gcloud projects add-iam-policy-binding $PROJECT \ | |
| # --member="serviceAccount:github-deployer@$PROJECT.iam.gserviceaccount.com" \ | |
| # --role=$role --condition=None | |
| # done | |
| # gcloud iam service-accounts keys create ../github-deployer-key.json \ | |
| # --iam-account=github-deployer@$PROJECT.iam.gserviceaccount.com | |
| # gh secret set GCLOUD_SERVICE_KEY < ../github-deployer-key.json | |
| # | |
| # (The key file lands one folder up — outside the repo, where git can't | |
| # reach it. Once gh has stored it, delete the file the ordinary way.) | |
| # | |
| # Note the SUPABASE_SECRET_KEY line in the deploy command is NOT a secret — | |
| # it's a reference to Google Secret Manager, where the real value lives. If | |
| # your API gains more secrets, add them to the same --update-secrets line as | |
| # comma-separated NAME=NAME:latest pairs after creating each in the vault. | |
| # | |
| ################################### | |
| name: Deploy to Cloud Run | |
| on: | |
| release: | |
| types: [published] | |
| env: | |
| # Your Cloud Run service — convention: <appname>-api-service | |
| SERVICE_NAME: yourapp-api-service | |
| # The region you deploy to | |
| GCP_REGION: us-east1 | |
| # Your production Supabase project URL (not a secret — the same value is | |
| # baked into every copy of the mobile app) | |
| SUPABASE_URL: https://yourproject.supabase.co | |
| # Flips to true once the deployer's key is in GitHub's vault; until then | |
| # every step below skips quietly. | |
| CONFIGURED: ${{ secrets.GCLOUD_SERVICE_KEY != '' }} | |
| jobs: | |
| deploy: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Deployment not configured yet — skipping | |
| if: env.CONFIGURED != 'true' | |
| run: echo "GCLOUD_SERVICE_KEY is not set, so there's nothing to deploy with. This is fine — see the one-time setup in this workflow's header." | |
| - name: Checkout repository | |
| if: env.CONFIGURED == 'true' | |
| uses: actions/checkout@v7 | |
| - name: Authenticate with Google Cloud | |
| if: env.CONFIGURED == 'true' | |
| uses: google-github-actions/auth@v2 | |
| with: | |
| credentials_json: ${{ secrets.GCLOUD_SERVICE_KEY }} | |
| - name: Set up gcloud | |
| if: env.CONFIGURED == 'true' | |
| uses: google-github-actions/setup-gcloud@v2 | |
| - name: Deploy to Cloud Run | |
| if: env.CONFIGURED == 'true' | |
| run: | | |
| # --clear-base-image: Cloud Run's managed base-image tracking can | |
| # refuse a REdeploy of a --source service without it. Harmless on | |
| # a first deploy. | |
| gcloud run deploy "$SERVICE_NAME" \ | |
| --source . \ | |
| --region "$GCP_REGION" \ | |
| --allow-unauthenticated \ | |
| --update-env-vars "APP_ENV=production,LOG_LEVEL=INFO,SUPABASE_URL=${SUPABASE_URL}" \ | |
| --update-secrets "SUPABASE_SECRET_KEY=SUPABASE_SECRET_KEY:latest" \ | |
| --clear-base-image \ | |
| --quiet | |
| - name: Show the service URL | |
| if: env.CONFIGURED == 'true' | |
| run: gcloud run services describe "$SERVICE_NAME" --region "$GCP_REGION" --format 'value(status.url)' |