Skip to content

Commit 61bb0a9

Browse files
John Kealyclaude
andcommitted
Align the deploy-key ceremony comment with the course
The key file lands in the workspace parent (outside the repo) and is deleted by hand once gh has stored it — the same ritual as every other robot key. Also note how to extend --update-secrets for further secrets. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
1 parent 845a60b commit 61bb0a9

1 file changed

Lines changed: 8 additions & 4 deletions

File tree

‎.github/workflows/gcp-deploy.yaml‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -30,13 +30,17 @@
3030
# --member="serviceAccount:github-deployer@$PROJECT.iam.gserviceaccount.com" \
3131
# --role=$role --condition=None
3232
# done
33-
# gcloud iam service-accounts keys create key.json \
33+
# gcloud iam service-accounts keys create ../github-deployer-key.json \
3434
# --iam-account=github-deployer@$PROJECT.iam.gserviceaccount.com
35-
# gh secret set GCLOUD_SERVICE_KEY < key.json
36-
# rm key.json
35+
# gh secret set GCLOUD_SERVICE_KEY < ../github-deployer-key.json
36+
#
37+
# (The key file lands one folder up — outside the repo, where git can't
38+
# reach it. Once gh has stored it, delete the file the ordinary way.)
3739
#
3840
# Note the SUPABASE_SECRET_KEY line in the deploy command is NOT a secret —
39-
# it's a reference to Google Secret Manager, where the real value lives.
41+
# it's a reference to Google Secret Manager, where the real value lives. If
42+
# your API gains more secrets, add them to the same --update-secrets line as
43+
# comma-separated NAME=NAME:latest pairs after creating each in the vault.
4044
#
4145
###################################
4246

0 commit comments

Comments
 (0)