Skip to content

Commit 4e64424

Browse files
authored
Switch to pull non-secret values from env (#624)
1 parent 32963c5 commit 4e64424

6 files changed

Lines changed: 14 additions & 14 deletions

File tree

.github/workflows/integration.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -84,28 +84,28 @@ jobs:
8484
- name: 'Set project ID'
8585
uses: './'
8686
with:
87-
project_id: '${{ secrets.PROJECT_ID }}'
87+
project_id: '${{ vars.PROJECT_ID }}'
8888

8989
- name: 'Check project ID'
9090
run: 'npm run integration'
9191
env:
92-
TEST_PROJECT_ID: '${{ secrets.PROJECT_ID }}'
92+
TEST_PROJECT_ID: '${{ vars.PROJECT_ID }}'
9393

9494
# Authenticate via WIF
9595
- name: 'Authenticate via WIF'
9696
uses: 'google-github-actions/auth@main'
9797
with:
98-
workload_identity_provider: '${{ secrets.WIF_PROVIDER_NAME }}'
99-
service_account: '${{ secrets.SERVICE_ACCOUNT_EMAIL }}'
98+
workload_identity_provider: '${{ vars.WIF_PROVIDER_NAME }}'
99+
service_account: '${{ vars.SERVICE_ACCOUNT_EMAIL }}'
100100

101101
- name: 'Setup gcloud with WIF'
102102
uses: './'
103103

104104
- name: 'Check WIF authentication'
105105
run: 'npm run integration'
106106
env:
107-
TEST_ACCOUNT: '${{ secrets.SERVICE_ACCOUNT_EMAIL }}'
108-
TEST_PROJECT_ID: '${{ secrets.PROJECT_ID }}'
107+
TEST_ACCOUNT: '${{ vars.SERVICE_ACCOUNT_EMAIL }}'
108+
TEST_PROJECT_ID: '${{ vars.PROJECT_ID }}'
109109

110110
# Authenticate via SAKE
111111
- name: 'Authenticate via SAKE'
@@ -119,5 +119,5 @@ jobs:
119119
- name: 'Check SAKE authentication'
120120
run: 'npm run integration'
121121
env:
122-
TEST_ACCOUNT: '${{ secrets.SERVICE_ACCOUNT_EMAIL }}'
123-
TEST_PROJECT_ID: '${{ secrets.PROJECT_ID }}'
122+
TEST_ACCOUNT: '${{ vars.SERVICE_ACCOUNT_EMAIL }}'
123+
TEST_PROJECT_ID: '${{ vars.PROJECT_ID }}'

example-workflows/cloud-build/.github/workflows/cloud-build.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ on:
2020
- 'main'
2121

2222
env:
23-
PROJECT_ID: ${{ secrets.RUN_PROJECT }}
23+
PROJECT_ID: ${{ vars.RUN_PROJECT }}
2424
SERVICE_NAME: helloworld-nodejs
2525

2626
jobs:
@@ -43,7 +43,7 @@ jobs:
4343
uses: 'google-github-actions/auth@v1'
4444
with:
4545
workload_identity_provider: 'projects/123456789/locations/global/workloadIdentityPools/my-pool/providers/my-provider'
46-
service_account: '${{ secrets.RUN_SA_EMAIL }}'
46+
service_account: '${{ vars.RUN_SA_EMAIL }}'
4747

4848
# Alternative option - authentication via credentials json
4949
# - id: 'auth'

example-workflows/cloud-run/cloud-run.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ on:
1919

2020
name: Build and Deploy to Cloud Run
2121
env:
22-
PROJECT_ID: ${{ secrets.GCP_PROJECT }}
22+
PROJECT_ID: ${{ vars.GCP_PROJECT }}
2323
SERVICE: YOUR_SERVICE_NAME
2424
REGION: YOUR_SERVICE_REGION
2525

example-workflows/gce/.github/workflows/gce.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ on:
2020
- 'main'
2121

2222
env:
23-
PROJECT_ID: ${{ secrets.GCE_PROJECT }}
23+
PROJECT_ID: ${{ vars.GCE_PROJECT }}
2424
GCE_INSTANCE: my-githubactions-vm # TODO: update to instance name
2525
GCE_INSTANCE_ZONE: us-central1-a # TODO: update to instance zone
2626

example-workflows/gke-kustomize/.github/workflows/gke-kustomize.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ on:
2020
- main
2121

2222
env:
23-
PROJECT_ID: ${{ secrets.GKE_PROJECT }}
23+
PROJECT_ID: ${{ vars.GKE_PROJECT }}
2424
GAR_LOCATION: us-central1 # # TODO: update region of the Artifact Registry
2525
GKE_CLUSTER: cluster-1 # TODO: update to cluster name
2626
GKE_ZONE: us-central1-c # TODO: update to cluster zone

example-workflows/gke/.github/workflows/gke.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ on:
2020
- main
2121

2222
env:
23-
PROJECT_ID: ${{ secrets.GKE_PROJECT }}
23+
PROJECT_ID: ${{ vars.GKE_PROJECT }}
2424
GKE_CLUSTER: cluster-1 # TODO: update to cluster name
2525
GKE_ZONE: europe-central2-a # TODO: update to cluster zone
2626
DEPLOYMENT_NAME: gke-hello-app # TODO: update deployment name if changed in deployment.yaml

0 commit comments

Comments
 (0)