Skip to content

0.5.4 — clear the managed base image on every Cloud Run deploy #12

0.5.4 — clear the managed base image on every Cloud Run deploy

0.5.4 — clear the managed base image on every Cloud Run deploy #12

Workflow file for this run

###################################
#
# GitHub Actions Workflow File - Deploy the Python API to GCP Cloud Run
#
# This workflow deploys the API to Google Cloud Run whenever a release is
# published — the same deliberate, named act that ships your database
# migrations. Publish a release, and both robots run: the schema and the
# code that expects it ship together.
#
# Until the one-time setup below is done, the workflow skips itself quietly
# (a green tick, nothing deployed) — a release made before deployment is
# configured is never marked as a failure.
#
# One-time setup (the course walks through this in "The Production Backend"):
#
# 1. Fill in the three values in the `env:` block below — your Cloud Run
# service name, region, and production Supabase URL.
#
# 2. Create a deployer service account and hand its key to GitHub. The key
# is the ONLY GitHub secret this workflow needs (it carries the project
# id inside it):
#
# PROJECT=<your-gcp-project-id>
# gcloud iam service-accounts create github-deployer \
# --display-name="GitHub Actions deployer" --project=$PROJECT
# for role in roles/run.admin roles/iam.serviceAccountUser \
# roles/cloudbuild.builds.editor roles/artifactregistry.admin \
# roles/storage.admin roles/serviceusage.serviceUsageConsumer; do
# gcloud projects add-iam-policy-binding $PROJECT \
# --member="serviceAccount:github-deployer@$PROJECT.iam.gserviceaccount.com" \
# --role=$role --condition=None
# done
# gcloud iam service-accounts keys create ../github-deployer-key.json \
# --iam-account=github-deployer@$PROJECT.iam.gserviceaccount.com
# gh secret set GCLOUD_SERVICE_KEY < ../github-deployer-key.json
#
# (The key file lands one folder up — outside the repo, where git can't
# reach it. Once gh has stored it, delete the file the ordinary way.)
#
# Note the SUPABASE_SECRET_KEY line in the deploy command is NOT a secret —
# it's a reference to Google Secret Manager, where the real value lives. If
# your API gains more secrets, add them to the same --update-secrets line as
# comma-separated NAME=NAME:latest pairs after creating each in the vault.
#
###################################
name: Deploy to Cloud Run
on:
release:
types: [published]
env:
# Your Cloud Run service — convention: <appname>-api-service
SERVICE_NAME: yourapp-api-service
# The region you deploy to
GCP_REGION: us-east1
# Your production Supabase project URL (not a secret — the same value is
# baked into every copy of the mobile app)
SUPABASE_URL: https://yourproject.supabase.co
# Flips to true once the deployer's key is in GitHub's vault; until then
# every step below skips quietly.
CONFIGURED: ${{ secrets.GCLOUD_SERVICE_KEY != '' }}
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- name: Deployment not configured yet — skipping
if: env.CONFIGURED != 'true'
run: echo "GCLOUD_SERVICE_KEY is not set, so there's nothing to deploy with. This is fine — see the one-time setup in this workflow's header."
- name: Checkout repository
if: env.CONFIGURED == 'true'
uses: actions/checkout@v7
- name: Authenticate with Google Cloud
if: env.CONFIGURED == 'true'
uses: google-github-actions/auth@v2
with:
credentials_json: ${{ secrets.GCLOUD_SERVICE_KEY }}
- name: Set up gcloud
if: env.CONFIGURED == 'true'
uses: google-github-actions/setup-gcloud@v2
- name: Deploy to Cloud Run
if: env.CONFIGURED == 'true'
run: |
# --clear-base-image: Cloud Run's managed base-image tracking can
# refuse a REdeploy of a --source service without it. Harmless on
# a first deploy.
gcloud run deploy "$SERVICE_NAME" \
--source . \
--region "$GCP_REGION" \
--allow-unauthenticated \
--update-env-vars "APP_ENV=production,LOG_LEVEL=INFO,SUPABASE_URL=${SUPABASE_URL}" \
--update-secrets "SUPABASE_SECRET_KEY=SUPABASE_SECRET_KEY:latest" \
--clear-base-image \
--quiet
- name: Show the service URL
if: env.CONFIGURED == 'true'
run: gcloud run services describe "$SERVICE_NAME" --region "$GCP_REGION" --format 'value(status.url)'